56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.468 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-30140 | HIGH 7.5 | microsoft windows_10 Windows iSCSI Discovery Service Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2026-50375 | MED 6.3 | microsoft windows_10_1809 Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally. | 1.8% | — |
| CVE-2025-26680 | HIGH 7.5 | microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | 1.8% | — |
| CVE-2022-35794 | HIGH 8.1 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2021-31172 | HIGH 7.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1.8% | — |
| CVE-2010-0023 | MED 6.9 | microsoft windows_2000 The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted applicati | 1.8% | — |
| CVE-2020-1220 | MED 6.1 | microsoft edge A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'. | 1.8% | — |
| CVE-2019-0553 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory, aka "Windows Subsystem for Linux Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019. | 1.8% | — |
| CVE-2023-44216 | MED 5.3 | amd ryzen_5_7600x PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For exam | 1.8% | — |
| CVE-2024-26226 | MED 6.5 | microsoft windows_server_2008 Windows Distributed File System (DFS) Information Disclosure Vulnerability | 1.8% | — |
| CVE-2002-2401 | LOW 3.6 | microsoft windows_2000 NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permissions for 16-bit executable files, which allows local users to bypass the loader and execute arbitrary programs. | 1.8% | — |
| CVE-2025-21348 | HIGH 7.2 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2020-1440 | MED 6.3 | microsoft sharepoint_enterprise_server <p>A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data.</p> <p>To exploit the vulnerability, an attacker | 1.8% | — |
| CVE-2020-16872 | HIGH 7.6 | microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially | 1.8% | — |
| CVE-2024-21372 | HIGH 8.8 | microsoft windows_10_1507 Windows OLE Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2013-3879 | HIGH 7.2 | microsoft windows_7 Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows loca | 1.8% | — |
| CVE-2013-3866 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a | 1.8% | — |
| CVE-2013-1341 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 8 allows local users to gain privileges via a crafted application, aka "Win32k | 1.8% | — |
| CVE-2013-0078 | HIGH 7.2 | microsoft windows_defender The Microsoft Antimalware Client in Windows Defender on Windows 8 and Windows RT uses an incorrect pathname for MsMpEng.exe, which allows local users to gain privileges via a crafted application, aka "Microsoft Antimalware Improper Pathname Vulnerability." | 1.8% | — |
| CVE-2005-2388 | HIGH 7.2 | microsoft windows_2000 Buffer overflow in a certain USB driver, as used on Microsoft Windows, allows attackers to execute arbitrary code. | 1.8% | — |
| CVE-2024-26205 | HIGH 8.8 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2024-26200 | HIGH 8.8 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2024-26179 | HIGH 8.8 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2023-29351 | HIGH 8.1 | microsoft windows_10_1507 Windows Group Policy Elevation of Privilege Vulnerability | 1.8% | — |
| CVE-2019-1000 | MED 5.3 | microsoft azure_active_directory_connect An elevation of privilege vulnerability exists in Microsoft Azure Active Directory Connect build 1.3.20.0, which allows an attacker to execute two PowerShell cmdlets in context of a privileged account, and perform privileged actions.To exploit this, an attacke | 1.8% | — |