56.586 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.468 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-8400 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID | 1.9% | — |
| CVE-2022-35802 | HIGH 8.1 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2019-1197 | MED 4.2 | microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 1.9% | — |
| CVE-2019-1196 | MED 4.2 | microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 1.9% | — |
| CVE-2019-1139 | MED 4.2 | microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 1.9% | — |
| CVE-2005-2935 | MED 4.6 | microsoft antispyware Unquoted Windows search path vulnerability in Microsoft AntiSpyware might allow local users to execute code via a malicious c:\program.exe file, which is run by AntiSpywareMain.exe when it attempts to execute gsasDtServ.exe. NOTE: it is not clear whether this | 1.9% | — |
| CVE-2021-4287 | MED 5.0 | microsoft binwalk A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2. Affected is an unknown function of the file src/binwalk/modules/extractor.py of the component Archive Extraction Handler. The manipulation leads to symlink foll | 1.9% | — |
| CVE-2026-41096 | CRIT 9.8 | microsoft windows_11_23h2 Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. | 1.9% | — |
| CVE-2010-0234 | MED 4.7 | microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate a registry-key argument to an unspecified system call, which allows local users to cause a denial of se | 1.9% | — |
| CVE-2021-31984 | HIGH 7.6 | microsoft power_bi_report_server Power BI Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2026-32184 | HIGH 7.8 | microsoft hpc_pack Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authorized attacker to elevate privileges locally. | 1.9% | — |
| CVE-2022-24472 | HIGH 8.0 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1.9% | — |
| CVE-2020-0624 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0642. | 1.9% | — |
| CVE-2004-0211 | LOW 2.1 | microsoft windows_2003_server The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program. | 1.9% | — |
| CVE-2026-32192 | HIGH 7.8 | microsoft azure_monitor_agent Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | 1.9% | — |
| CVE-2024-20663 | MED 6.5 | microsoft windows_10_1507 Windows Message Queuing Client (MSMQC) Information Disclosure | 1.9% | — |
| CVE-2000-0088 | HIGH 7.2 | microsoft office Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malformed Conversion Data" vulnerability. | 1.9% | — |
| CVE-2011-0039 | HIGH 7.2 | microsoft windows_2003_server The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length | 1.9% | — |
| CVE-2023-36433 | MED 6.5 | microsoft dynamics_365 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | 1.9% | — |
| CVE-2024-26165 | HIGH 8.8 | microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2017-0096 | LOW 2.6 | microsoft windows_10 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to obtain sensitive information from host OS mem | 1.9% | — |
| CVE-2015-2534 | LOW 1.9 | microsoft windows_10 Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 improperly processes ACL settings, which allows local users to bypass intended network-traffic restrictions via a crafted application, aka "Hyper-V Security Feature Bypass Vulnerability." | 1.9% | — |
| CVE-2026-50433 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | 1.9% | — |
| CVE-2026-50387 | HIGH 7.8 | microsoft 365_copilot Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally. | 1.9% | — |
| CVE-2026-54986 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | 1.9% | — |