IT
56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.468 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-30181 MED 6.5 microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability 1.8%
CVE-2019-0743 MED 5.4 microsoft team_foundation_server A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0742. 1.8%
CVE-2019-0742 MED 5.4 microsoft team_foundation_server A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0743. 1.8%
CVE-2010-2740 HIGH 7.2 microsoft windows_2003_server The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly perform memory allocation during font parsing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Parsing Vul 1.8%
CVE-2020-1205 MED 4.6 microsoft sharepoint_enterprise_server <p>A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to 1.8%
CVE-2013-3907 HIGH 7.2 microsoft windows_7 portcls.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka "Port-Class Driver Dou 1.8%
CVE-2002-2324 HIGH 7.2 microsoft windows_xp The "System Restore" directory and subdirectories, and possibly other subdirectories in the "System Volume Information" directory on Windows XP Professional, have insecure access control list (ACL) permissions, which allows local users to access restricted fil 1.8%
CVE-2026-27909 HIGH 7.8 microsoft windows_10_1607 Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. 1.8%
CVE-2010-3960 MED 4.9 microsoft windows_server_2008 Hyper-V in Microsoft Windows Server 2008 Gold, SP2, and R2 allows guest OS users to cause a denial of service (host OS hang) by sending a crafted encapsulated packet over the VMBus, aka "Hyper-V VMBus Vulnerability." 1.8%
CVE-2024-30101 HIGH 7.5 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 1.8%
CVE-2024-21370 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.8%
CVE-2024-21366 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.8%
CVE-2024-21365 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.8%
CVE-2024-21360 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.8%
CVE-2024-21358 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.8%
CVE-2023-35365 CRIT 9.8 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.8%
CVE-2014-2780 MED 6.9 microsoft windows_7 DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows local users to gain privileges by leveraging control over a low-integrity process to execute a craf 1.8%
CVE-2014-1807 HIGH 7.2 microsoft windows_7 The ShellExecute API in Windows Shell in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly implement f 1.8%
CVE-2002-0373 HIGH 7.2 microsoft windows_media_player The Windows Media Device Manager (WMDM) Service in Microsoft Windows Media Player 7.1 on Windows 2000 systems allows local users to obtain LocalSystem rights via a program that calls the WMDM service to connect to an invalid local storage device, aka "Privileg 1.8%
CVE-2026-58289 CRIT 9.0 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 1.8%
CVE-2023-21803 CRIT 9.8 microsoft windows_10 Windows iSCSI Discovery Service Remote Code Execution Vulnerability 1.8%
CVE-2013-3154 MED 6.9 microsoft windows_7 The signature-update functionality in Windows Defender on Microsoft Windows 7 and Windows Server 2008 R2 relies on an incorrect pathname, which allows local users to gain privileges via a Trojan horse application in the %SYSTEMDRIVE% top-level directory, aka " 1.8%
CVE-2011-0030 MED 4.7 microsoft windows_2003_server The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that con 1.8%
CVE-2023-35317 HIGH 7.8 microsoft windows_server_2012 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability 1.8%
CVE-2018-8654 MED 6.5 microsoft dynamics_365 An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Server, aka 'Microsoft Dynamics 365 Elevation of Privilege Vulnerability'. 1.8%