IT
56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.468 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-36407 HIGH 7.8 microsoft windows_11_21h2 Windows Hyper-V Elevation of Privilege Vulnerability 1.7%
CVE-2020-1442 MED 6.1 microsoft office_online_server A spoofing vulnerability exists when an Office Web Apps server does not properly sanitize a specially crafted request, aka 'Office Web Apps XSS Vulnerability'. 1.7%
CVE-2019-0759 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows Print Spooler does not properly handle objects in memory, aka 'Windows Print Spooler Information Disclosure Vulnerability'. 1.7%
CVE-2024-21380 HIGH 8.0 microsoft dynamics_365_business_central Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability 1.7%
CVE-2020-16985 MED 6.2 microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability 1.7%
CVE-2018-8428 MED 5.4 microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft 1.7%
CVE-2019-0886 MED 6.8 microsoft windows_10 An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'. 1.7%
CVE-2005-0060 HIGH 7.2 microsoft windows_2000 Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application. 1.7%
CVE-2023-21543 HIGH 8.1 microsoft windows_10_1607 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability 1.7%
CVE-2015-0084 LOW 2.1 microsoft windows_7 The Task Scheduler in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local users to bypass intended restri 1.7%
CVE-2013-2553 HIGH 7.2 microsoft windows_7 Unspecified vulnerability in the kernel in Microsoft Windows 7 allows local users to gain privileges via unknown vectors, as demonstrated by Nils and Jon of MWR Labs during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0912. 1.7%
CVE-2013-1280 HIGH 7.2 microsoft windows_7 The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows 1.7%
CVE-2012-1866 HIGH 7.2 microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver 1.7%
CVE-2019-0928 MED 6.2 microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. 1.7%
CVE-2026-50688 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 1.7%
CVE-2024-21379 HIGH 7.8 microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability 1.7%
CVE-1999-1556 HIGH 7.2 microsoft sql_server Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value. 1.7%
CVE-2022-33680 HIGH 8.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.7%
CVE-2010-0719 MED 4.7 microsoft windows_2000 An unspecified API in Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 does not validate arguments, which allows local users to cause a denial of service (system crash) via a crafted application. 1.7%
CVE-2024-30097 HIGH 8.8 microsoft windows_10_1507 Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability 1.7%
CVE-2024-30009 HIGH 8.8 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.7%
CVE-2024-30006 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.7%
CVE-2020-1101 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra 1.7%
CVE-2020-1100 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra 1.7%
CVE-2020-1099 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra 1.7%