IT
56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.463 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-1400 MED 5.5 microsoft office An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1463. 2.2%
CVE-2021-34474 HIGH 8.0 microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability 2.2%
CVE-2018-0900 MED 4.7 microsoft windows_10 The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information discl 2.2%
CVE-2018-0899 MED 4.7 microsoft windows_10 The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information discl 2.2%
CVE-2018-0898 MED 4.7 microsoft windows_10 The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information discl 2.2%
CVE-2024-38072 HIGH 7.5 microsoft windows_server_2016 Windows Remote Desktop Licensing Service Denial of Service Vulnerability 2.2%
CVE-2024-38041 MED 5.5 microsoft windows_10_1607 Windows Kernel Information Disclosure Vulnerability 2.2%
CVE-2023-29328 HIGH 8.8 microsoft teams Microsoft Teams Remote Code Execution Vulnerability 2.2%
CVE-2025-62472 HIGH 7.8 microsoft windows_10_1607 Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. 2.2%
CVE-2025-21220 HIGH 7.5 microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability 2.2%
CVE-2016-0048 HIGH 7.8 microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application 2.1%
CVE-2022-35837 MED 6.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 2.1%
CVE-2021-24105 HIGH 8.4 microsoft package_manager_configurations <p>Depending on configuration of various package managers it is possible for an attacker to insert a malicious package into a package manager's repository which can be retrieved and used during development, build, and release processes. This insertion could le 2.1%
CVE-2023-33150 CRIT 9.6 microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability 2.1%
CVE-2021-31983 HIGH 7.8 microsoft paint_3d Paint 3D Remote Code Execution Vulnerability 2.1%
CVE-2017-8654 MED 5.4 microsoft sharepoint_server Microsoft SharePoint Server 2010 Service Pack 2 allows a cross-site scripting (XSS) vulnerability when it does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability". 2.1%
CVE-2022-23274 HIGH 8.8 microsoft dynamics_gp Microsoft Dynamics GP Remote Code Execution Vulnerability 2.1%
CVE-2013-1333 HIGH 7.2 microsoft windows_7 Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overflow Vulnerability." 2.1%
CVE-2022-24487 HIGH 8.8 microsoft windows_10 Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability 2.1%
CVE-2026-33116 HIGH 7.5 microsoft .net Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network. 2.1%
CVE-2018-8221 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2.1%
CVE-2018-8217 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2.1%
CVE-2018-8216 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2.1%
CVE-2018-8215 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2.1%
CVE-2018-8211 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows 10 Serv 2.1%