IT
56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.463 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-30173 HIGH 7.8 microsoft excel Microsoft Excel Remote Code Execution Vulnerability 2.2%
CVE-2021-43889 HIGH 7.2 microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability 2.2%
CVE-2021-40453 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 2.2%
CVE-2025-21308 MED 6.5 microsoft windows_10_1507 Windows Themes Spoofing Vulnerability 2.2%
CVE-2023-35377 MED 6.5 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2.2%
CVE-2023-35376 MED 6.5 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 2.2%
CVE-2021-34452 HIGH 7.8 microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability 2.2%
CVE-2023-32057 CRIT 9.8 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 2.2%
CVE-2021-34506 MED 6.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability 2.2%
CVE-2023-49283 MED 5.4 microsoft graph microsoft-graph-core the Microsoft Graph Library for PHP. The Microsoft Graph Beta PHP SDK published packages which contained test code that enabled the use of the phpInfo() function from any application that could access and execute the file at `vendor/micros 2.2%
CVE-2023-49282 MED 5.4 microsoft graph msgraph-sdk-php is the Microsoft Graph Library for PHP. The Microsoft Graph PHP SDK published packages which contained test code that enabled the use of the phpInfo() function from any application that could access and execute the file at vendor/microsoft/micr 2.2%
CVE-2022-22039 HIGH 7.5 microsoft windows_server_2008 Windows Network File System Remote Code Execution Vulnerability 2.2%
CVE-2023-38174 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability 2.2%
CVE-2022-23273 HIGH 7.1 microsoft dynamics_gp Microsoft Dynamics GP Elevation Of Privilege Vulnerability 2.2%
CVE-2019-0839 MED 4.4 microsoft windows_10 An information disclosure vulnerability exists when the Terminal Services component improperly discloses the contents of its memory, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0838. 2.2%
CVE-2019-1337 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when Windows Update Client fails to properly handle objects in memory, aka 'Windows Update Client Information Disclosure Vulnerability'. 2.2%
CVE-2021-34441 HIGH 7.8 microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability 2.2%
CVE-2021-34438 HIGH 7.8 microsoft windows_10 Windows Font Driver Host Remote Code Execution Vulnerability 2.2%
CVE-2020-1164 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerabilit 2.2%
CVE-2020-1151 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerabilit 2.2%
CVE-2020-1149 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerabilit 2.2%
CVE-2020-1125 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerabilit 2.2%
CVE-2017-11852 MED 4.7 microsoft windows_7 Microsoft GDI Component in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker to log on to an affected system and run a specially crafted application to compromise the user's system, due improperly disclosing kernel memory addresses, aka " 2.2%
CVE-2024-21400 CRIT 9.0 microsoft confidental_containers Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability 2.2%
CVE-2024-38064 HIGH 7.5 microsoft windows_10_1507 Windows TCP/IP Information Disclosure Vulnerability 2.2%