56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.463 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2009-2069 | MED 5.8 | microsoft ie Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certific | 2.2% | — |
| CVE-2020-16996 | MED 6.5 | microsoft windows_server_2012 Kerberos Security Feature Bypass Vulnerability | 2.2% | — |
| CVE-2001-1302 | LOW 2.1 | microsoft windows_2000 The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem i | 2.2% | — |
| CVE-2024-37966 | HIGH 7.1 | microsoft sql_server_2017 Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | 2.2% | — |
| CVE-2022-30206 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2020-17162 | HIGH 8.8 | microsoft windows_10 Microsoft Windows Security Feature Bypass Vulnerability | 2.2% | — |
| CVE-2024-38074 | CRIT 9.8 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2023-36893 | MED 6.5 | microsoft 365_apps Microsoft Outlook Spoofing Vulnerability | 2.2% | — |
| CVE-2021-1712 | HIGH 8.0 | microsoft sharepoint_enterprise_server Microsoft SharePoint Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2014-6602 | MED 6.6 | microsoft nokia_asha_501 Microsoft Asha OS on the Microsoft Mobile Nokia Asha 501 phone 14.0.4 allows physically proximate attackers to bypass the lock-screen protection mechanism, and read or modify contact information or dial arbitrary telephone numbers, by tapping the SOS Option an | 2.2% | — |
| CVE-2018-0869 | MED 5.4 | microsoft sharepoint_enterprise_server SharePoint Server 2016 allows an elevation of privilege vulnerability due to how web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". | 2.2% | — |
| CVE-2022-37981 | MED 4.3 | microsoft windows_10 Windows Event Logging Service Denial of Service Vulnerability | 2.2% | — |
| CVE-2017-11880 | MED 4.7 | microsoft windows_10 Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to run a specially crafted application and obtain informa | 2.2% | — |
| CVE-2017-11849 | MED 4.7 | microsoft windows_10 Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially | 2.2% | — |
| CVE-2017-11842 | MED 4.7 | microsoft windows_10 Windows kernel in Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially crafted application due to the Windows kernel impr | 2.2% | — |
| CVE-2023-36723 | HIGH 7.8 | microsoft windows_10_1809 Windows Container Manager Service Elevation of Privilege Vulnerability | 2.2% | — |
| CVE-2021-42294 | HIGH 7.2 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2016-7221 | HIGH 7.8 | microsoft windows_10 Input Method Editor (IME) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 mishandles DLL loading, which al | 2.2% | — |
| CVE-2022-26907 | MED 5.3 | microsoft azure_sdk_for_.net Azure SDK for .NET Information Disclosure Vulnerability | 2.2% | — |
| CVE-2025-29814 | CRIT 9.3 | microsoft partner_center Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. | 2.2% | — |
| CVE-2024-21348 | HIGH 7.5 | microsoft windows_10_1507 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 2.2% | — |
| CVE-2021-42279 | MED 4.2 | microsoft windows_10 Chakra Scripting Engine Memory Corruption Vulnerability | 2.2% | — |
| CVE-2002-0720 | HIGH 7.2 | microsoft windows_2000 A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code. | 2.2% | — |
| CVE-2022-38036 | HIGH 7.5 | microsoft windows_11 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | 2.2% | — |
| CVE-2022-33645 | HIGH 7.5 | microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability | 2.2% | — |