IT
56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.468 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-30140 HIGH 7.5 microsoft windows_10 Windows iSCSI Discovery Service Remote Code Execution Vulnerability 1.8%
CVE-2026-50375 MED 6.3 microsoft windows_10_1809 Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally. 1.8%
CVE-2025-26680 HIGH 7.5 microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. 1.8%
CVE-2022-35794 HIGH 8.1 microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 1.8%
CVE-2021-31172 HIGH 7.1 microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability 1.8%
CVE-2010-0023 MED 6.9 microsoft windows_2000 The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted applicati 1.8%
CVE-2020-1220 MED 6.1 microsoft edge A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'. 1.8%
CVE-2019-0553 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory, aka "Windows Subsystem for Linux Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019. 1.8%
CVE-2023-44216 MED 5.3 amd ryzen_5_7600x PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For exam 1.8%
CVE-2024-26226 MED 6.5 microsoft windows_server_2008 Windows Distributed File System (DFS) Information Disclosure Vulnerability 1.8%
CVE-2002-2401 LOW 3.6 microsoft windows_2000 NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permissions for 16-bit executable files, which allows local users to bypass the loader and execute arbitrary programs. 1.8%
CVE-2025-21348 HIGH 7.2 microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability 1.8%
CVE-2020-1440 MED 6.3 microsoft sharepoint_enterprise_server <p>A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data.</p> <p>To exploit the vulnerability, an attacker 1.8%
CVE-2020-16872 HIGH 7.6 microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially 1.8%
CVE-2024-21372 HIGH 8.8 microsoft windows_10_1507 Windows OLE Remote Code Execution Vulnerability 1.8%
CVE-2013-3879 HIGH 7.2 microsoft windows_7 Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows loca 1.8%
CVE-2013-3866 HIGH 7.2 microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a 1.8%
CVE-2013-1341 HIGH 7.2 microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 8 allows local users to gain privileges via a crafted application, aka "Win32k 1.8%
CVE-2013-0078 HIGH 7.2 microsoft windows_defender The Microsoft Antimalware Client in Windows Defender on Windows 8 and Windows RT uses an incorrect pathname for MsMpEng.exe, which allows local users to gain privileges via a crafted application, aka "Microsoft Antimalware Improper Pathname Vulnerability." 1.8%
CVE-2005-2388 HIGH 7.2 microsoft windows_2000 Buffer overflow in a certain USB driver, as used on Microsoft Windows, allows attackers to execute arbitrary code. 1.8%
CVE-2024-26205 HIGH 8.8 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.8%
CVE-2024-26200 HIGH 8.8 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.8%
CVE-2024-26179 HIGH 8.8 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.8%
CVE-2023-29351 HIGH 8.1 microsoft windows_10_1507 Windows Group Policy Elevation of Privilege Vulnerability 1.8%
CVE-2019-1000 MED 5.3 microsoft azure_active_directory_connect An elevation of privilege vulnerability exists in Microsoft Azure Active Directory Connect build 1.3.20.0, which allows an attacker to execute two PowerShell cmdlets in context of a privileged account, and perform privileged actions.To exploit this, an attacke 1.8%