56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.463 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36567 | HIGH 7.5 | microsoft windows_10_1507 Windows Deployment Services Information Disclosure Vulnerability | 2.0% | — |
| CVE-2023-29348 | HIGH 7.5 | microsoft windows_server_2008 Windows Remote Desktop Gateway (RD Gateway) Information Disclosure Vulnerability | 2.0% | — |
| CVE-2023-21757 | HIGH 7.5 | microsoft windows_10 Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability | 2.0% | — |
| CVE-2022-30145 | HIGH 7.5 | microsoft windows_10 Windows Encrypting File System (EFS) Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2022-37976 | HIGH 8.8 | microsoft windows_server_2008 Active Directory Certificate Services Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2001-0048 | HIGH 7.2 | microsoft windows_2000 The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Rest | 2.0% | — |
| CVE-2015-0011 | MED 4.7 | microsoft windows_7 mrxdav.sys (aka the WebDAV driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow | 2.0% | — |
| CVE-2022-22024 | HIGH 7.8 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2026-42986 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 2.0% | — |
| CVE-2026-42905 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 2.0% | — |
| CVE-2017-0244 | MED 6.7 | microsoft windows_7 The kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows locally authenticated attackers to gain privileges via a crafted application, or in Windows 7 for x64-based systems, cause denial of service, aka "Windows Kernel Elevation of Privilege | 2.0% | — |
| CVE-2007-5470 | LOW 2.1 | microsoft expression_media Microsoft Expression Media stores the catalog password in cleartext in the catalog IVC file, which allows local users to obtain sensitive information and gain access to the catalog by reading the IVC file. | 2.0% | — |
| CVE-2013-3903 | MED 4.7 | microsoft windows_8 Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to cause a denial of service (reboot) via a crafted TrueType font (TTF) file, aka "TrueType Font | 2.0% | — |
| CVE-2018-8417 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Microsoft JScript that could allow an attacker to bypass Device Guard, aka "Microsoft JScript Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 1 | 2.0% | — |
| CVE-2020-1096 | MED 4.2 | microsoft edge A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of the current user. An att | 2.0% | — |
| CVE-2023-36012 | MED 5.3 | microsoft windows_server_2008 DHCP Server Service Information Disclosure Vulnerability | 2.0% | — |
| CVE-2021-31938 | HIGH 7.3 | microsoft kubernetes_tools Microsoft VsCode Kubernetes Tools Extension Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2024-20664 | MED 6.5 | microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability | 2.0% | — |
| CVE-1999-1294 | LOW 2.1 | microsoft windows_nt Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission. | 2.0% | — |
| CVE-2019-0558 | MED 5.4 | microsoft business_productivity_servers A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoi | 2.0% | — |
| CVE-2015-1758 | MED 6.9 | microsoft windows_7 Untrusted search path vulnerability in the LoadLibrary function in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a Trojan h | 2.0% | — |
| CVE-2024-29993 | HIGH 8.8 | microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2021-42310 | HIGH 8.1 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2022-26918 | HIGH 7.8 | microsoft windows_10 Windows Fax Compose Form Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2022-26916 | HIGH 7.8 | microsoft windows_10 Windows Fax Compose Form Remote Code Execution Vulnerability | 2.0% | — |