IT
56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.463 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-38160 CRIT 9.1 microsoft windows_10_1607 Windows Network Virtualization Remote Code Execution Vulnerability 2.2%
CVE-2024-38159 CRIT 9.1 microsoft windows_10_1607 Windows Network Virtualization Remote Code Execution Vulnerability 2.2%
CVE-2021-42315 HIGH 8.8 microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability 2.2%
CVE-2021-42314 HIGH 8.8 microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability 2.2%
CVE-2021-31942 HIGH 7.8 microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability 2.2%
CVE-1999-1217 MED 4.6 microsoft windows_nt The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories. 2.2%
CVE-2024-38076 CRIT 9.8 microsoft windows_server_2016 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability 2.2%
CVE-2022-30193 HIGH 7.8 microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability 2.2%
CVE-2022-30180 HIGH 7.8 microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Information Disclosure Vulnerability 2.2%
CVE-2022-30178 HIGH 7.8 microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability 2.2%
CVE-2022-30177 HIGH 7.8 microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability 2.2%
CVE-2022-30167 HIGH 7.8 microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability 2.2%
CVE-2022-29119 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 2.2%
CVE-2022-22018 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 2.2%
CVE-2022-30139 HIGH 7.5 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 2.2%
CVE-2020-1065 MED 4.2 microsoft chakracore A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An at 2.2%
CVE-2020-1037 MED 4.2 microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context 2.2%
CVE-2025-47178 HIGH 8.0 microsoft configuration_manager_2503 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execute code over an adjacent network. 2.2%
CVE-2014-0262 HIGH 7.2 microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Server 2008 R2 SP1 does not properly consider thread-owned objects during the processing of window handles, which allows local users to gain privileges via a crafted application, aka "Win32k 2.2%
CVE-2020-0976 MED 5.4 microsoft sharepoint_enterprise_server A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-0972, CVE-2020- 2.2%
CVE-2024-26183 MED 6.5 microsoft windows_10_1507 Windows Kerberos Denial of Service Vulnerability 2.2%
CVE-2019-1363 MED 5.5 microsoft windows_7 An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'. 2.2%
CVE-2000-0933 MED 4.6 microsoft windows_2000 The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the "Simplified Chinese IME State Recogniti 2.2%
CVE-2021-40442 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 2.2%
CVE-2019-1463 MED 5.5 microsoft office An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1400. 2.2%