56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.468 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-0815 | HIGH 7.5 | microsoft azure_devops_server An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability'. This CVE ID is unique from | 1.8% | — |
| CVE-2025-47733 | CRIT 9.1 | microsoft power_apps Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network | 1.8% | — |
| CVE-2018-8622 | MED 5.5 | microsoft windows_7 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows | 1.8% | — |
| CVE-2018-8621 | MED 5.5 | microsoft windows_7 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows Server 2012, Windows 7, Windows Server 2008 R2. This CVE ID is unique f | 1.8% | — |
| CVE-2017-0025 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges v | 1.8% | — |
| CVE-1999-0503 | HIGH 7.2 | microsoft windows_2000 A Windows NT local user or administrator account has a guessable password. | 1.8% | — |
| CVE-2024-43624 | HIGH 8.8 | microsoft windows_10_1809 Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability | 1.8% | — |
| CVE-2022-38046 | HIGH 7.5 | microsoft windows_10 Web Account Manager Information Disclosure Vulnerability | 1.8% | — |
| CVE-2022-24534 | HIGH 7.5 | microsoft windows_10 Win32 Stream Enumeration Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2024-38109 | CRIT 9.1 | microsoft azure_health_bot An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network. | 1.8% | — |
| CVE-2023-36706 | MED 6.5 | microsoft windows_server_2008 Windows Deployment Services Information Disclosure Vulnerability | 1.8% | — |
| CVE-2022-26905 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1.8% | — |
| CVE-2024-43481 | MED 6.5 | microsoft power_bi_report_server Power BI Report Server Spoofing Vulnerability | 1.8% | — |
| CVE-2011-0088 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain pri | 1.8% | — |
| CVE-2011-0087 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka " | 1.8% | — |
| CVE-2025-21172 | HIGH 7.5 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2010-3957 | HIGH 7.3 | microsoft windows_2003_server Double free vulnerability in the OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted OpenTy | 1.8% | — |
| CVE-2026-62888 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 1.8% | — |
| CVE-2026-62783 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 1.8% | — |
| CVE-2010-0810 | MED 4.7 | microsoft windows_server_2008 The kernel in Microsoft Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, does not properly handle unspecified exceptions, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Excep | 1.8% | — |
| CVE-2010-0235 | MED 4.7 | microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not perform the expected validation before creating a symbolic link, which allows local users to cause a denial of service (reboot) via a crafted application, aka "W | 1.8% | — |
| CVE-2021-1717 | MED 4.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.8% | — |
| CVE-2021-1641 | MED 4.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.8% | — |
| CVE-2020-0924 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- | 1.8% | — |
| CVE-2005-0545 | HIGH 7.2 | microsoft windows_2000 Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group policies that restrict access to hidden drives by using the browse feature in Office 10 applications such as Word or Excel, or using a flash dri | 1.8% | — |