IT
56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.468 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-24035 HIGH 8.1 microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. 1.8%
CVE-2021-1728 HIGH 8.8 microsoft system_center_operations_manager System Center Operations Manager Elevation of Privilege Vulnerability 1.8%
CVE-2024-38104 HIGH 8.8 microsoft windows_10_1507 Windows Fax Service Remote Code Execution Vulnerability 1.8%
CVE-2023-35329 MED 6.5 microsoft windows_10_1507 Windows Authentication Denial of Service Vulnerability 1.8%
CVE-2024-26221 HIGH 7.2 microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability 1.8%
CVE-2025-29968 MED 6.5 microsoft windows_server_2008 Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network. 1.8%
CVE-2019-0975 MED 6.3 microsoft windows_server_2016 A security feature bypass vulnerability exists when Active Directory Federation Services (ADFS) improperly updates its list of banned IP addresses. To exploit this vulnerability, an attacker would have to convince a victim ADFS administrator to update the list 1.8%
CVE-2017-8515 MED 5.5 microsoft windows_10 Microsoft Windows 10 1511, 1607, and 1703, and Windows Server 2016 allow an unauthenticated attacker to send a specially crafted kernel mode request to cause a denial of service on the target system, aka "Windows VAD Cloning Denial of Service Vulnerability". 1.8%
CVE-2014-0318 HIGH 7.2 microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly control acc 1.8%
CVE-2024-43475 HIGH 7.3 microsoft windows_server_2008 Microsoft Windows Admin Center Information Disclosure Vulnerability 1.8%
CVE-2021-38631 MED 4.4 microsoft windows_10 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability 1.8%
CVE-2020-1327 MED 6.1 microsoft azure_devops_server A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'. 1.8%
CVE-2001-0502 MED 4.6 microsoft windows_2000 Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login password o 1.8%
CVE-2020-16884 MED 4.2 microsoft edge <p>A remote code execution vulnerability exists in the way that the IEToEdge Browser Helper Object (BHO) plugin on Internet Explorer handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code i 1.8%
CVE-2018-8638 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Information Disclosure Vulnerability." This affects Windows 10, Windows Server 2019. 1.8%
CVE-1999-1317 MED 4.6 microsoft windows_nt Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device. 1.8%
CVE-2024-38116 HIGH 8.8 microsoft windows_10_1507 Windows IP Routing Management Snapin Remote Code Execution Vulnerability 1.8%
CVE-2007-6753 MED 6.2 microsoft windows_2000 Untrusted search path vulnerability in Shell32.dll in Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2008, and Windows 7, when using an environment configured with a string such as %APPDATA% or %PROGRAMFILES% in a certain way, allows local u 1.8%
CVE-2021-1730 MED 5.4 microsoft exchange_server <p>A spoofing vulnerability exists in Microsoft Exchange Server which could result in an attack that would allow a malicious actor to impersonate the user.</p> <p>This update addresses this vulnerability.</p> <p>To prevent these types of attacks, Microsoft rec 1.8%
CVE-2019-1105 MED 5.4 microsoft outlook A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted email message to a victim. The attacker who s 1.8%
CVE-2015-0073 HIGH 7.2 microsoft windows_7 The Windows Registry Virtualization feature in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict changes 1.8%
CVE-2012-2529 HIGH 7.2 microsoft windows_7 Integer overflow in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages i 1.8%
CVE-2022-30149 HIGH 7.5 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 1.8%
CVE-2022-30146 HIGH 7.5 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 1.8%
CVE-2022-30143 HIGH 7.5 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 1.8%