56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.468 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1210 | CRIT 9.9 | microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the ShareP | 1.8% | — |
| CVE-2021-43229 | HIGH 7.8 | microsoft windows_10 Windows NTFS Elevation of Privilege Vulnerability | 1.8% | — |
| CVE-2010-2741 | HIGH 7.2 | microsoft windows_2003_server The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 performs an incorrect integer calculation during font processing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Validation | 1.8% | — |
| CVE-2023-21713 | HIGH 8.8 | microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2019-1077 | MED 5.0 | microsoft visual_studio_2017 An elevation of privilege vulnerability exists when the Visual Studio updater service improperly handles file permissions, aka 'Visual Studio Elevation of Privilege Vulnerability'. | 1.8% | — |
| CVE-2015-1644 | HIGH 7.2 | microsoft windows_7 Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local use | 1.8% | — |
| CVE-2026-26171 | HIGH 7.5 | microsoft .net Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network. | 1.8% | — |
| CVE-2020-17131 | MED 4.2 | microsoft chakracore Chakra Scripting Engine Memory Corruption Vulnerability | 1.8% | — |
| CVE-2023-28312 | MED 6.5 | microsoft azure_machine_learning Azure Machine Learning Information Disclosure Vulnerability | 1.8% | — |
| CVE-2013-3898 | HIGH 7.9 | microsoft windows_8 Microsoft Windows 8 and Windows Server 2012, when Hyper-V is used, does not ensure memory-address validity, which allows guest OS users to execute arbitrary code in all guest OS instances, and allows guest OS users to cause a denial of service (host OS crash), | 1.8% | — |
| CVE-2024-26222 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1.8% | — |
| CVE-2019-1483 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerab | 1.8% | — |
| CVE-2017-8745 | MED 5.4 | microsoft sharepoint_foundation An elevation of privilege vulnerability exists in Microsoft SharePoint Foundation 2013 Service Pack 1 when it does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Cross Site Scripting Vulnerabil | 1.8% | — |
| CVE-2015-0062 | HIGH 7.2 | microsoft windows_7 Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to gain privileges via a crafted application that leverages incorrect impersonation handling in a proces | 1.8% | — |
| CVE-2012-2553 | HIGH 7.2 | microsoft windows_7 Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, | 1.8% | — |
| CVE-2012-2530 | HIGH 7.2 | microsoft windows_7 Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via | 1.8% | — |
| CVE-2024-38239 | HIGH 7.2 | microsoft windows_10_1507 Windows Kerberos Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2020-1501 | MED 5.4 | microsoft sharepoint_enterprise_server A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an | 1.7% | — |
| CVE-2002-2132 | LOW 2.1 | microsoft windows_2000 Windows File Protection (WFP) in Windows 2000 and XP does not remove old security catalog .CAT files, which could allow local users to replace new files with vulnerable old files that have valid hash codes. | 1.7% | — |
| CVE-2000-1217 | MED 4.6 | microsoft windows_2000 Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited numb | 1.7% | — |
| CVE-2024-30054 | MED 6.5 | microsoft powerbi-javascript Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability | 1.7% | — |
| CVE-2006-2374 | MED 5.5 | microsoft windows_2000 The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the | 1.7% | — |
| CVE-2023-29343 | HIGH 7.8 | microsoft windows_sysmon SysInternals Sysmon for Windows Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2021-28444 | MED 5.7 | microsoft windows_10 Windows Hyper-V Security Feature Bypass Vulnerability | 1.7% | — |
| CVE-2023-21719 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 1.7% | — |