56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.463 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-21683 | HIGH 7.5 | microsoft windows_10_1607 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-21677 | HIGH 7.5 | microsoft windows_10_1607 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-21527 | HIGH 7.5 | microsoft windows_10_1607 Windows iSCSI Service Denial of Service Vulnerability | 2.0% | — |
| CVE-2021-33746 | HIGH 8.0 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-1639 | HIGH 7.0 | microsoft visual_studio_2017 Visual Studio Code Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2026-40368 | HIGH 8.0 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2.0% | — |
| CVE-2013-5046 | MED 6.2 | microsoft internet_explorer Microsoft Internet Explorer 7 through 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability." | 2.0% | — |
| CVE-2023-36787 | HIGH 8.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2021-1726 | HIGH 8.0 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 2.0% | — |
| CVE-2018-8222 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server | 2.0% | — |
| CVE-2023-36906 | MED 5.5 | microsoft windows_10 Windows Cryptographic Services Information Disclosure Vulnerability | 2.0% | — |
| CVE-2010-1889 | HIGH 7.8 | microsoft windows_server_2008 Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka "Windows Kernel D | 2.0% | — |
| CVE-2011-2018 | HIGH 7.2 | microsoft windows_7 The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, and Windows 7 Gold and SP1 does not properly initialize objects, which allows local users to gain privileges via a crafted application, aka "Wi | 2.0% | — |
| CVE-2002-2028 | LOW 2.1 | microsoft windows_2000 The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has already been locked when a valid password is provided, which makes it easier for users with physical access to conduct brute force password guessing. | 2.0% | — |
| CVE-2023-38172 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.0% | — |
| CVE-2021-42275 | HIGH 8.8 | microsoft windows_10 Microsoft COM for Windows Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2019-0622 | MED 4.6 | microsoft skype An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Android Elevation of Privilege Vulnerability." This affects Skype 8.35. | 2.0% | — |
| CVE-2015-2465 | LOW 2.1 | microsoft windows_10 The Windows shell in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 does not properly constrain impersonation levels, which allows | 2.0% | — |
| CVE-2026-33110 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2.0% | — |
| CVE-2022-35774 | MED 4.9 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2022-41058 | HIGH 7.5 | microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.0% | — |
| CVE-2022-41053 | HIGH 7.5 | microsoft windows_10 Windows Kerberos Denial of Service Vulnerability | 2.0% | — |
| CVE-2024-30090 | HIGH 7.0 | microsoft windows_10_1507 Microsoft Streaming Service Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2022-30211 | HIGH 7.5 | microsoft windows_10 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-33754 | HIGH 8.0 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 2.0% | — |