IT
56.586 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.468 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2018-8400 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID 1.9%
CVE-2022-35802 HIGH 8.1 microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability 1.9%
CVE-2019-1197 MED 4.2 microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context 1.9%
CVE-2019-1196 MED 4.2 microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context 1.9%
CVE-2019-1139 MED 4.2 microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context 1.9%
CVE-2005-2935 MED 4.6 microsoft antispyware Unquoted Windows search path vulnerability in Microsoft AntiSpyware might allow local users to execute code via a malicious c:\program.exe file, which is run by AntiSpywareMain.exe when it attempts to execute gsasDtServ.exe. NOTE: it is not clear whether this 1.9%
CVE-2021-4287 MED 5.0 microsoft binwalk A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2. Affected is an unknown function of the file src/binwalk/modules/extractor.py of the component Archive Extraction Handler. The manipulation leads to symlink foll 1.9%
CVE-2026-41096 CRIT 9.8 microsoft windows_11_23h2 Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. 1.9%
CVE-2010-0234 MED 4.7 microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate a registry-key argument to an unspecified system call, which allows local users to cause a denial of se 1.9%
CVE-2021-31984 HIGH 7.6 microsoft power_bi_report_server Power BI Remote Code Execution Vulnerability 1.9%
CVE-2026-32184 HIGH 7.8 microsoft hpc_pack Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authorized attacker to elevate privileges locally. 1.9%
CVE-2022-24472 HIGH 8.0 microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability 1.9%
CVE-2020-0624 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0642. 1.9%
CVE-2004-0211 LOW 2.1 microsoft windows_2003_server The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program. 1.9%
CVE-2026-32192 HIGH 7.8 microsoft azure_monitor_agent Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. 1.9%
CVE-2024-20663 MED 6.5 microsoft windows_10_1507 Windows Message Queuing Client (MSMQC) Information Disclosure 1.9%
CVE-2000-0088 HIGH 7.2 microsoft office Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malformed Conversion Data" vulnerability. 1.9%
CVE-2011-0039 HIGH 7.2 microsoft windows_2003_server The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length 1.9%
CVE-2023-36433 MED 6.5 microsoft dynamics_365 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability 1.9%
CVE-2024-26165 HIGH 8.8 microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability 1.9%
CVE-2017-0096 LOW 2.6 microsoft windows_10 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to obtain sensitive information from host OS mem 1.9%
CVE-2015-2534 LOW 1.9 microsoft windows_10 Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 improperly processes ACL settings, which allows local users to bypass intended network-traffic restrictions via a crafted application, aka "Hyper-V Security Feature Bypass Vulnerability." 1.9%
CVE-2026-50433 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Media allows an authorized attacker to elevate privileges locally. 1.9%
CVE-2026-50387 HIGH 7.8 microsoft 365_copilot Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally. 1.9%
CVE-2026-54986 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. 1.9%