56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.463 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-30142 | HIGH 7.5 | microsoft windows_10 Windows File History Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2024-38044 | HIGH 7.2 | microsoft windows_server_2012 DHCP Server Service Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2020-1172 | MED 4.2 | microsoft chakracore <p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An | 2.1% | — |
| CVE-2022-26898 | HIGH 7.2 | microsoft azure_site_recovery Azure Site Recovery Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2021-31963 | HIGH 7.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2020-17130 | MED 6.5 | microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability | 2.1% | — |
| CVE-2021-28455 | HIGH 8.8 | microsoft 365_apps Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2022-22027 | HIGH 7.8 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2026-33835 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 2.1% | — |
| CVE-2024-43512 | MED 6.5 | microsoft windows_server_2012 Windows Standards-Based Storage Management Service Denial of Service Vulnerability | 2.1% | — |
| CVE-2019-1369 | MED 5.5 | microsoft open_enclave_software_development_kit An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'. | 2.1% | — |
| CVE-2011-1283 | HIGH 7.2 | microsoft windows_2003_server The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 does not ensure that an unspecified array index has a non-nega | 2.1% | — |
| CVE-2011-1281 | HIGH 7.2 | microsoft windows_2003_server The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly restric | 2.1% | — |
| CVE-2026-49800 | HIGH 7.8 | microsoft windows_10_1809 Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally. | 2.1% | — |
| CVE-2020-0965 | HIGH 7.8 | microsoft windows_10 A remoted code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. | 2.1% | — |
| CVE-2006-0488 | LOW 2.1 | microsoft windows_2000 The VDM (Virtual DOS Machine) emulation environment for MS-DOS applications in Windows 2000, Windows XP SP2, and Windows Server 2003 allows local users to read the first megabyte of memory and possibly obtain sensitive information, as demonstrated by dumper.as | 2.1% | — |
| CVE-2025-58722 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DWM allows an authorized attacker to elevate privileges locally. | 2.1% | — |
| CVE-2025-21207 | HIGH 7.5 | microsoft windows_10_1809 Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability | 2.1% | — |
| CVE-2024-26164 | HIGH 8.8 | microsoft django_backend Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2017-0155 | HIGH 7.0 | microsoft windows_7 The Graphics component in the kernel in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Graphics Elevation of Privilege Vulnerability." | 2.1% | — |
| CVE-2025-21350 | MED 5.9 | microsoft windows_10_1507 Windows Kerberos Denial of Service Vulnerability | 2.1% | — |
| CVE-2019-0858 | MED 6.1 | microsoft exchange_server A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0817. | 2.1% | — |
| CVE-2010-0238 | MED 4.9 | microsoft windows_2000 Unspecified vulnerability in registry-key validation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Registry K | 2.1% | — |
| CVE-2024-49033 | HIGH 7.5 | microsoft 365_apps Microsoft Word Security Feature Bypass Vulnerability | 2.1% | — |
| CVE-2022-35827 | HIGH 8.8 | microsoft visual_studio Visual Studio Remote Code Execution Vulnerability | 2.1% | — |