56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.463 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-32030 | HIGH 7.5 | microsoft .net_framework .NET and Visual Studio Denial of Service Vulnerability | 2.2% | — |
| CVE-2024-43565 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.2% | — |
| CVE-2024-43562 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.2% | — |
| CVE-2024-43545 | HIGH 7.5 | microsoft windows_server_2008 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability | 2.2% | — |
| CVE-2024-43544 | HIGH 7.5 | microsoft windows_server_2008 Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability | 2.2% | — |
| CVE-2022-33677 | HIGH 7.2 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2022-33633 | HIGH 7.2 | microsoft lync_server Skype for Business and Lync Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-26422 | HIGH 7.2 | microsoft lync_server Skype for Business and Lync Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-1719 | HIGH 8.0 | microsoft sharepoint_enterprise_server Microsoft SharePoint Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2007-5460 | MED 4.6 | microsoft windows_mobile Microsoft ActiveSync 4.1, as used in Windows Mobile 5.0, uses weak encryption (XOR obfuscation with a fixed key) when sending the user's PIN/Password over the USB connection from the host to the device, which might make it easier for attackers to decode a PIN/ | 2.2% | — |
| CVE-2024-26202 | HIGH 7.2 | microsoft windows_server_2012 DHCP Server Service Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2024-26195 | HIGH 7.2 | microsoft windows_server_2008 DHCP Server Service Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-36941 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2020-1523 | HIGH 8.9 | microsoft sharepoint_server <p>A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data.</p> <p>To exploit the vulnerability, an attacker | 2.2% | — |
| CVE-2002-0507 | LOW 2.1 | microsoft exchange_server An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, | 2.2% | — |
| CVE-2018-8212 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server | 2.2% | — |
| CVE-2017-8486 | MED 4.7 | microsoft windows_10 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure due to the way it handles objects in memory, ak | 2.2% | — |
| CVE-2024-28915 | HIGH 8.8 | microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2024-28911 | HIGH 8.8 | microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2022-24516 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2022-26785 | MED 6.5 | microsoft windows_server_2016 Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability | 2.2% | — |
| CVE-2025-21299 | HIGH 7.1 | microsoft windows_10_1507 Windows Kerberos Security Feature Bypass Vulnerability | 2.2% | — |
| CVE-2021-42316 | HIGH 8.8 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2025-47175 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | 2.2% | — |
| CVE-2016-3306 | HIGH 7.8 | microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 mishandles session objects, which allows local users to hijack sessi | 2.2% | — |