56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.463 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-27470 | HIGH 7.5 | microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | 2.1% | — |
| CVE-2025-26652 | HIGH 7.5 | microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | 2.1% | — |
| CVE-2022-33658 | MED 4.9 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 2.1% | — |
| CVE-2022-33652 | MED 4.9 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 2.1% | — |
| CVE-2021-26882 | HIGH 7.8 | microsoft windows_10 Remote Access API Elevation of Privilege Vulnerability | 2.1% | — |
| CVE-2019-3800 | MED 6.3 | anynines elasticsearch CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as t | 2.1% | — |
| CVE-2023-28267 | MED 6.5 | microsoft remote_desktop_client Remote Desktop Protocol Client Information Disclosure Vulnerability | 2.1% | — |
| CVE-2022-30134 | MED 6.5 | microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability | 2.1% | — |
| CVE-2024-20652 | HIGH 8.1 | microsoft windows_10_1507 Windows HTML Platforms Security Feature Bypass Vulnerability | 2.1% | — |
| CVE-2022-24477 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 2.1% | — |
| CVE-2019-0798 | MED 6.1 | microsoft lync_server A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vulnerability'. | 2.1% | — |
| CVE-2023-24937 | MED 6.5 | microsoft windows_10_1809 Windows CryptoAPI Denial of Service Vulnerability | 2.1% | — |
| CVE-2021-1706 | HIGH 7.3 | microsoft windows_10 Windows LUAFV Elevation of Privilege Vulnerability | 2.1% | — |
| CVE-2010-0819 | HIGH 7.2 | microsoft windows_2000 Unspecified vulnerability in the Windows OpenType Compact Font Format (CFF) driver in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users to execute arbitrary code via unknown | 2.1% | — |
| CVE-2023-35390 | HIGH 7.8 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2018-0747 | MED 4.7 | microsoft windows_10 The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulne | 2.1% | — |
| CVE-2024-21356 | MED 6.5 | microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | 2.1% | — |
| CVE-2021-31173 | MED 5.3 | microsoft sharepoint_foundation Microsoft SharePoint Server Information Disclosure Vulnerability | 2.1% | — |
| CVE-2013-3198 | HIGH 7.2 | microsoft windows_7 The NT Virtual DOS Machine (NTVDM) subsystem in the kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly validate kernel-memory addresses, wh | 2.1% | — |
| CVE-2013-3197 | HIGH 7.2 | microsoft windows_7 The NT Virtual DOS Machine (NTVDM) subsystem in the kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly validate kernel-memory addresses, wh | 2.1% | — |
| CVE-2013-3196 | HIGH 7.2 | microsoft windows_7 The NT Virtual DOS Machine (NTVDM) subsystem in the kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly validate kernel-memory addresses, wh | 2.1% | — |
| CVE-2024-38229 | HIGH 8.1 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2024-21314 | MED 6.5 | microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability | 2.1% | — |
| CVE-2011-0090 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain pri | 2.1% | — |
| CVE-2019-1422 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the iphlpsvc.dll handles file creation allowing for a file overwrite, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1420, CVE-2019-1423. | 2.1% | — |