56.587 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.468 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-54114 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 1.9% | — |
| CVE-2024-20662 | MED 4.9 | microsoft windows_server_2008 Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability | 1.9% | — |
| CVE-2025-27486 | HIGH 7.5 | microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | 1.9% | — |
| CVE-2025-27485 | HIGH 7.5 | microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | 1.9% | — |
| CVE-2025-21174 | HIGH 7.5 | microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | 1.9% | — |
| CVE-2010-2554 | HIGH 7.8 | microsoft windows_7 The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on its registry keys, which allows local users to gain privileges via vectors involving a named pipe and impersonat | 1.9% | — |
| CVE-2021-43876 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2001-0344 | HIGH 7.2 | microsoft sql_server An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account. | 1.9% | — |
| CVE-2021-1705 | MED 4.2 | microsoft edge Microsoft Edge (HTML-based) Memory Corruption Vulnerability | 1.9% | — |
| CVE-2020-1200 | HIGH 8.6 | microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the ShareP | 1.9% | — |
| CVE-2026-26142 | CRIT 9.8 | microsoft nuance_powerscribe_360 Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network. | 1.9% | — |
| CVE-2021-33753 | MED 4.7 | microsoft bing Microsoft Bing Search Spoofing Vulnerability | 1.9% | — |
| CVE-2005-4697 | LOW 2.1 | microsoft windows_xp The Microsoft Wireless Zero Configuration system (WZCS) allows local users to access WEP keys and pair-wise Master Keys (PMK) of the WPA pre-shared key via certain calls to the WZCQueryInterface API function in wzcsapi.dll. | 1.9% | — |
| CVE-2024-30017 | HIGH 8.8 | microsoft windows_10_1507 Windows Hyper-V Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2025-21307 | CRIT 9.8 | microsoft windows_10_1507 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2026-64901 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.9% | — |
| CVE-2025-21224 | HIGH 8.1 | microsoft windows_10_21h2 Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2023-36763 | HIGH 7.5 | microsoft 365_apps Microsoft Outlook Information Disclosure Vulnerability | 1.9% | — |
| CVE-2021-41350 | MED 6.5 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 1.9% | — |
| CVE-2026-66808 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.9% | — |
| CVE-2026-66805 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.9% | — |
| CVE-2015-1720 | HIGH 7.2 | microsoft windows_7 Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 | 1.9% | — |
| CVE-2022-37977 | MED 6.5 | microsoft windows_10 Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | 1.9% | — |
| CVE-2025-49683 | HIGH 7.8 | microsoft windows_10_1507 Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally. | 1.9% | — |
| CVE-2023-35391 | MED 6.2 | microsoft .net ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability | 1.9% | — |