IT
56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.463 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-55232 CRIT 9.8 microsoft hpc_pack Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network. 2.1%
CVE-2020-1059 MED 4.3 microsoft edge A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content. An attacker who successfully exploited this vulnerability could trick a user by redirecting the user to a specially crafted website. The specially crafted website could e 2.1%
CVE-2025-62204 HIGH 8.0 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 2.1%
CVE-2023-33148 HIGH 7.8 microsoft 365_apps Microsoft Office Elevation of Privilege Vulnerability 2.1%
CVE-2020-17153 MED 4.3 microsoft edge Microsoft Edge for Android Spoofing Vulnerability 2.1%
CVE-2017-0043 MED 5.3 microsoft windows_10 Active Directory Federation Services in Microsoft Windows 10 1607, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016 allows local users to obtain sensitive information via a crafted application, aka "Microsoft Active 2.1%
CVE-2019-0838 HIGH 7.8 microsoft windows_10 An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0839. 2.1%
CVE-2018-8437 MED 6.2 microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability." This affects Windows 10, 2.1%
CVE-2018-8436 MED 6.2 microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability." This affects Windows 10, 2.1%
CVE-2017-8712 MED 5.3 microsoft windows_10 The Windows Hyper-V component on Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information D 2.1%
CVE-2017-8711 MED 5.3 microsoft windows_10 The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosu 2.1%
CVE-2001-0666 LOW 2.1 microsoft exchange_server Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox. 2.1%
CVE-2017-0189 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows 10 when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode, aka "Win32k Elevatio 2.1%
CVE-2026-26127 HIGH 7.5 microsoft .net Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network. 2.0%
CVE-2020-17015 MED 4.3 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 2.0%
CVE-2019-0986 MED 6.3 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To exploit this vulnera 2.0%
CVE-2001-1497 LOW 2.1 microsoft ie Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier t 2.0%
CVE-2022-26917 HIGH 7.8 microsoft windows_10 Windows Fax Compose Form Remote Code Execution Vulnerability 2.0%
CVE-2022-24473 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 2.0%
CVE-2021-34447 MED 6.8 microsoft windows_10 Windows MSHTML Platform Remote Code Execution Vulnerability 2.0%
CVE-2021-34446 HIGH 8.0 microsoft windows_10 Windows HTML Platforms Security Feature Bypass Vulnerability 2.0%
CVE-2026-21262 HIGH 8.8 microsoft sql_server_2016 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. 2.0%
CVE-2025-47978 MED 6.5 microsoft windows_server_2022 Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. 2.0%
CVE-2022-37955 HIGH 7.8 microsoft windows_10 Windows Group Policy Elevation of Privilege Vulnerability 2.0%
CVE-2021-28447 MED 4.4 microsoft windows_10 Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability 2.0%