IT
56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.463 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-26244 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 2.0%
CVE-2024-26210 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 2.0%
CVE-2014-1814 HIGH 7.2 microsoft windows_7 The Windows Installer in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a c 2.0%
CVE-2000-0663 MED 4.6 microsoft windows_2000 The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, 2.0%
CVE-2025-47165 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 2.0%
CVE-2025-21330 HIGH 7.5 microsoft windows_10_1809 Windows Remote Desktop Services Denial of Service Vulnerability 2.0%
CVE-2023-35338 HIGH 7.5 microsoft windows_10_1507 Windows Peer Name Resolution Protocol Denial of Service Vulnerability 2.0%
CVE-2021-24109 MED 6.8 microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability 2.0%
CVE-2010-1887 MED 4.4 microsoft windows_2003_server The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate an unspecified system-call argument, which allo 2.0%
CVE-2023-29363 CRIT 9.8 microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability 2.0%
CVE-2016-0020 HIGH 7.8 microsoft windows_7 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "MAPI DLL Loading Elevation of Privilege Vulnerability." 2.0%
CVE-2013-6999 MED 4.0 microsoft windows_server_2008 The IsHandleEntrySecure function in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 SP2 does not properly validate the tagPROCESSINFO pW32Job field, which allows local users to cause a denial of service (NULL pointer dereference and syst 2.0%
CVE-2021-28458 HIGH 7.8 microsoft ms-rest-nodeauth Azure ms-rest-nodeauth Library Elevation of Privilege Vulnerability 2.0%
CVE-2019-0869 MED 6.1 microsoft azure_devops_server A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'. 2.0%
CVE-2013-3173 HIGH 7.2 microsoft windows_7 Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to ga 2.0%
CVE-2020-1595 CRIT 9.9 microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application 2.0%
CVE-2019-1440 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1436. 2.0%
CVE-2022-38006 MED 6.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 2.0%
CVE-2026-62741 HIGH 7.8 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 2.0%
CVE-2026-61930 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 2.0%
CVE-2023-36437 HIGH 8.8 microsoft azure_pipelines_agent Azure DevOps Server Remote Code Execution Vulnerability 2.0%
CVE-2015-2454 LOW 2.1 microsoft windows_7 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local 2.0%
CVE-2026-62713 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 1.9%
CVE-2026-58536 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 1.9%
CVE-2026-50329 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 1.9%