IT
56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.463 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-24931 HIGH 7.5 microsoft windows_10_1507 Windows Secure Channel Denial of Service Vulnerability 2.0%
CVE-2023-21557 HIGH 7.5 microsoft windows_10_1607 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability 2.0%
CVE-2024-26214 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC SQL Server ODBC Driver Remote Code Execution Vulnerability 2.0%
CVE-2024-26162 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 2.0%
CVE-2022-24462 MED 5.5 microsoft 365_apps Microsoft Word Security Feature Bypass Vulnerability 2.0%
CVE-2014-1819 HIGH 7.2 microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly control acc 2.0%
CVE-2021-34496 MED 5.5 microsoft windows_10 Windows GDI Information Disclosure Vulnerability 2.0%
CVE-2019-0636 MED 5.5 microsoft windows_10 An information vulnerability exists when Windows improperly discloses file information, aka 'Windows Information Disclosure Vulnerability'. 2.0%
CVE-2018-8492 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2.0%
CVE-2017-8554 MED 4.7 microsoft windows_10 The kernel in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an authenticated attacker to obtain memory contents via 2.0%
CVE-2026-26132 HIGH 7.8 microsoft windows_10_21h2 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 2.0%
CVE-2023-28303 LOW 3.3 microsoft snip_\&_sketch Windows Snipping Tool Information Disclosure Vulnerability 2.0%
CVE-2022-39344 CRIT 9.8 microsoft azure_rtos_usbx Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. Prior to version 6.1.12, the USB DFU UPLOAD functionality may be utilized to introduce a buffer overflow resulting in overwrite of memo 2.0%
CVE-2016-3231 HIGH 7.8 microsoft windows_diagnostics_hub The Standard Collector service in Windows Diagnostics Hub mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Windows Diagnostics Hub Elevation of Privilege Vulnerability." 2.0%
CVE-2022-21987 HIGH 8.0 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 2.0%
CVE-2025-27479 HIGH 7.5 microsoft windows_server_2012 Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network. 2.0%
CVE-2025-27473 HIGH 7.5 microsoft windows_10_1507 Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. 2.0%
CVE-2022-30221 HIGH 8.8 microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability 2.0%
CVE-2020-0758 HIGH 7.5 microsoft azure_devops_server An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability'. This CVE ID is unique from 2.0%
CVE-2026-33840 HIGH 7.8 microsoft windows_11_24h2 Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. 2.0%
CVE-2019-1442 MED 5.5 microsoft sharepoint_server A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerab 2.0%
CVE-2026-50667 HIGH 7.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally. 2.0%
CVE-2020-1195 LOW 3.1 microsoft edge An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly validates input. An attacker who successfully exploited this vulnerability could write files to arbitrary locations and gain elevated privi 2.0%
CVE-2022-24460 HIGH 7.0 microsoft windows_10 Tablet Windows User Interface Application Elevation of Privilege Vulnerability 2.0%
CVE-2024-43609 MED 6.5 microsoft 365_apps Microsoft Office Spoofing Vulnerability 2.0%