56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.468 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-30076 | MED 6.8 | microsoft windows_10_1607 Windows Container Manager Service Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2019-0600 | MED 4.7 | microsoft windows_10 An information disclosure vulnerability exists when the Human Interface Devices (HID) component improperly handles objects in memory, aka 'HID Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0601. | 1.7% | — |
| CVE-2018-8205 | MED 5.5 | microsoft windows_10 A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Wi | 1.7% | — |
| CVE-2018-8602 | MED 5.4 | microsoft team_foundation_server A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka "Team Foundation Server Cross-site Scripting Vulnerability." This affects Team. | 1.7% | — |
| CVE-2017-0021 | CRIT 9.0 | microsoft windows_10 Hyper-V in Microsoft Windows 10 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary code on a target OS, aka "Hyper-V System Data Structure Vulnerability." This vulnerability is different from t | 1.7% | — |
| CVE-2011-1967 | HIGH 7.2 | microsoft windows_2003_server Winsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check p | 1.7% | — |
| CVE-2026-65665 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.7% | — |
| CVE-2025-47987 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally. | 1.7% | — |
| CVE-2023-36911 | CRIT 9.8 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2018-0750 | MED 5.5 | microsoft windows_7 The Windows GDI component in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Windows Elevation of Privilege Vulnerability". | 1.7% | — |
| CVE-2024-49080 | HIGH 8.8 | microsoft windows_10_1507 Windows IP Routing Management Snapin Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2024-49057 | HIGH 8.1 | microsoft defender_for_endpoint Microsoft Defender for Endpoint on Android Spoofing Vulnerability | 1.7% | — |
| CVE-2007-1221 | HIGH 7.2 | microsoft xbox_360 The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 allows attackers with physical access to force execution of the hypervisor syscall with a certain register set, which bypasses intended code protection. | 1.7% | — |
| CVE-2024-37965 | HIGH 8.8 | microsoft sql_server_2016 Microsoft SQL Server Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2020-16991 | HIGH 7.3 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1.7% | — |
| CVE-2011-2010 | HIGH 7.2 | microsoft pinyin_ime The Microsoft Office Input Method Editor (IME) for Simplified Chinese in Microsoft Pinyin IME 2010, Office Pinyin SimpleFast Style 2010, and Office Pinyin New Experience Style 2010 does not properly restrict access to configuration options, which allows local | 1.7% | — |
| CVE-2005-1982 | LOW 3.6 | microsoft windows_2000 Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when P | 1.7% | — |
| CVE-2001-0547 | LOW 2.1 | microsoft isa_server Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion). | 1.7% | — |
| CVE-2023-36021 | HIGH 8.0 | microsoft on-prem_data_gateway Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability | 1.7% | — |
| CVE-2019-1251 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1244, CVE-2019-1245. | 1.7% | — |
| CVE-2019-1219 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Transaction Manager improperly handles objects in memory, aka 'Windows Transaction Manager Information Disclosure Vulnerability'. | 1.7% | — |
| CVE-2019-1216 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Information Disclosure Vulnerability'. | 1.7% | — |
| CVE-2026-40357 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.7% | — |
| CVE-2025-21171 | HIGH 7.5 | microsoft .net .NET Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2023-36897 | HIGH 8.1 | microsoft 365_apps Visual Studio Tools for Office Runtime Spoofing Vulnerability | 1.7% | — |