IT
56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.468 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-1210 CRIT 9.9 microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the ShareP 1.8%
CVE-2021-43229 HIGH 7.8 microsoft windows_10 Windows NTFS Elevation of Privilege Vulnerability 1.8%
CVE-2010-2741 HIGH 7.2 microsoft windows_2003_server The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 performs an incorrect integer calculation during font processing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Validation 1.8%
CVE-2023-21713 HIGH 8.8 microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability 1.8%
CVE-2019-1077 MED 5.0 microsoft visual_studio_2017 An elevation of privilege vulnerability exists when the Visual Studio updater service improperly handles file permissions, aka 'Visual Studio Elevation of Privilege Vulnerability'. 1.8%
CVE-2015-1644 HIGH 7.2 microsoft windows_7 Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local use 1.8%
CVE-2026-26171 HIGH 7.5 microsoft .net Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network. 1.8%
CVE-2020-17131 MED 4.2 microsoft chakracore Chakra Scripting Engine Memory Corruption Vulnerability 1.8%
CVE-2023-28312 MED 6.5 microsoft azure_machine_learning Azure Machine Learning Information Disclosure Vulnerability 1.8%
CVE-2013-3898 HIGH 7.9 microsoft windows_8 Microsoft Windows 8 and Windows Server 2012, when Hyper-V is used, does not ensure memory-address validity, which allows guest OS users to execute arbitrary code in all guest OS instances, and allows guest OS users to cause a denial of service (host OS crash), 1.8%
CVE-2024-26222 HIGH 7.2 microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability 1.8%
CVE-2019-1483 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerab 1.8%
CVE-2017-8745 MED 5.4 microsoft sharepoint_foundation An elevation of privilege vulnerability exists in Microsoft SharePoint Foundation 2013 Service Pack 1 when it does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Cross Site Scripting Vulnerabil 1.8%
CVE-2015-0062 HIGH 7.2 microsoft windows_7 Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to gain privileges via a crafted application that leverages incorrect impersonation handling in a proces 1.8%
CVE-2012-2553 HIGH 7.2 microsoft windows_7 Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, 1.8%
CVE-2012-2530 HIGH 7.2 microsoft windows_7 Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via 1.8%
CVE-2024-38239 HIGH 7.2 microsoft windows_10_1507 Windows Kerberos Elevation of Privilege Vulnerability 1.7%
CVE-2020-1501 MED 5.4 microsoft sharepoint_enterprise_server A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an 1.7%
CVE-2002-2132 LOW 2.1 microsoft windows_2000 Windows File Protection (WFP) in Windows 2000 and XP does not remove old security catalog .CAT files, which could allow local users to replace new files with vulnerable old files that have valid hash codes. 1.7%
CVE-2000-1217 MED 4.6 microsoft windows_2000 Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited numb 1.7%
CVE-2024-30054 MED 6.5 microsoft powerbi-javascript Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability 1.7%
CVE-2006-2374 MED 5.5 microsoft windows_2000 The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the 1.7%
CVE-2023-29343 HIGH 7.8 microsoft windows_sysmon SysInternals Sysmon for Windows Elevation of Privilege Vulnerability 1.7%
CVE-2021-28444 MED 5.7 microsoft windows_10 Windows Hyper-V Security Feature Bypass Vulnerability 1.7%
CVE-2023-21719 MED 6.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability 1.7%