IT
56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.468 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-30076 MED 6.8 microsoft windows_10_1607 Windows Container Manager Service Elevation of Privilege Vulnerability 1.7%
CVE-2019-0600 MED 4.7 microsoft windows_10 An information disclosure vulnerability exists when the Human Interface Devices (HID) component improperly handles objects in memory, aka 'HID Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0601. 1.7%
CVE-2018-8205 MED 5.5 microsoft windows_10 A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Wi 1.7%
CVE-2018-8602 MED 5.4 microsoft team_foundation_server A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka "Team Foundation Server Cross-site Scripting Vulnerability." This affects Team. 1.7%
CVE-2017-0021 CRIT 9.0 microsoft windows_10 Hyper-V in Microsoft Windows 10 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary code on a target OS, aka "Hyper-V System Data Structure Vulnerability." This vulnerability is different from t 1.7%
CVE-2011-1967 HIGH 7.2 microsoft windows_2003_server Winsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check p 1.7%
CVE-2026-65665 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.7%
CVE-2025-47987 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally. 1.7%
CVE-2023-36911 CRIT 9.8 microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.7%
CVE-2018-0750 MED 5.5 microsoft windows_7 The Windows GDI component in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Windows Elevation of Privilege Vulnerability". 1.7%
CVE-2024-49080 HIGH 8.8 microsoft windows_10_1507 Windows IP Routing Management Snapin Remote Code Execution Vulnerability 1.7%
CVE-2024-49057 HIGH 8.1 microsoft defender_for_endpoint Microsoft Defender for Endpoint on Android Spoofing Vulnerability 1.7%
CVE-2007-1221 HIGH 7.2 microsoft xbox_360 The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 allows attackers with physical access to force execution of the hypervisor syscall with a certain register set, which bypasses intended code protection. 1.7%
CVE-2024-37965 HIGH 8.8 microsoft sql_server_2016 Microsoft SQL Server Elevation of Privilege Vulnerability 1.7%
CVE-2020-16991 HIGH 7.3 microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability 1.7%
CVE-2011-2010 HIGH 7.2 microsoft pinyin_ime The Microsoft Office Input Method Editor (IME) for Simplified Chinese in Microsoft Pinyin IME 2010, Office Pinyin SimpleFast Style 2010, and Office Pinyin New Experience Style 2010 does not properly restrict access to configuration options, which allows local 1.7%
CVE-2005-1982 LOW 3.6 microsoft windows_2000 Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when P 1.7%
CVE-2001-0547 LOW 2.1 microsoft isa_server Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion). 1.7%
CVE-2023-36021 HIGH 8.0 microsoft on-prem_data_gateway Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability 1.7%
CVE-2019-1251 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1244, CVE-2019-1245. 1.7%
CVE-2019-1219 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows Transaction Manager improperly handles objects in memory, aka 'Windows Transaction Manager Information Disclosure Vulnerability'. 1.7%
CVE-2019-1216 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Information Disclosure Vulnerability'. 1.7%
CVE-2026-40357 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.7%
CVE-2025-21171 HIGH 7.5 microsoft .net .NET Remote Code Execution Vulnerability 1.7%
CVE-2023-36897 HIGH 8.1 microsoft 365_apps Visual Studio Tools for Office Runtime Spoofing Vulnerability 1.7%