56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.468 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2006-5585 | HIGH 7.2 | microsoft windows_2003_server The Client-Server Run-time Subsystem in Microsoft Windows XP SP2 and Server 2003 allows local users to gain privileges via a crafted file manifest within an application, aka "File Manifest Corruption Vulnerability." | 1.7% | — |
| CVE-2022-38009 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2013-3878 | MED 6.9 | microsoft windows_server_2003 Stack-based buffer overflow in the LRPC client in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges by operating an LRPC server that sends a crafted LPC port message, aka "LRPC Client Buffer Overrun Vulnerability." | 1.7% | — |
| CVE-2013-1345 | HIGH 7.2 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, | 1.7% | — |
| CVE-2023-33136 | HIGH 8.8 | microsoft azure_devops_server Azure DevOps Server Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2019-1097 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1093. | 1.7% | — |
| CVE-2019-1093 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1097. | 1.7% | — |
| CVE-2006-3209 | HIGH 7.2 | microsoft windows_xp The Task scheduler (at.exe) on Microsoft Windows XP spawns each scheduled process with SYSTEM permissions, which allows local users to gain privileges. NOTE: this issue has been disputed by third parties, who state that the Task scheduler is limited to the Ad | 1.7% | — |
| CVE-2023-36577 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2022-35782 | MED 6.5 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2022-35781 | MED 6.5 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2022-35780 | MED 6.5 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2022-35775 | MED 6.5 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2018-0926 | MED 5.5 | microsoft windows_10 The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information discl | 1.7% | — |
| CVE-2013-1334 | HIGH 7.2 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, | 1.7% | — |
| CVE-2023-21816 | HIGH 7.5 | microsoft windows_10 Windows Active Directory Domain Services API Denial of Service Vulnerability | 1.7% | — |
| CVE-2025-27482 | HIGH 8.1 | microsoft windows_server_2016 Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | 1.7% | — |
| CVE-2022-30215 | HIGH 7.5 | microsoft windows_server_2016 Active Directory Federation Services Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2023-36419 | HIGH 8.8 | microsoft azure_hdinsight Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2023-36907 | MED 5.5 | microsoft windows_10 Windows Cryptographic Services Information Disclosure Vulnerability | 1.7% | — |
| CVE-2023-36905 | MED 5.5 | microsoft windows_10 Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | 1.7% | — |
| CVE-2021-43214 | HIGH 7.8 | microsoft raw_image_extension Web Media Extensions Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2023-28234 | HIGH 7.5 | microsoft windows_11_21h2 Windows Secure Channel Denial of Service Vulnerability | 1.7% | — |
| CVE-2023-28233 | HIGH 7.5 | microsoft windows_11_21h2 Windows Secure Channel Denial of Service Vulnerability | 1.7% | — |
| CVE-2024-21420 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.7% | — |