56.588 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.468 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-0979 | MED 5.4 | microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique f | 1.7% | — |
| CVE-2019-0872 | MED 5.4 | microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique f | 1.7% | — |
| CVE-2019-0777 | MED 5.4 | microsoft team_foundation_server A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'. | 1.7% | — |
| CVE-2002-0643 | MED 4.6 | microsoft data_engine The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted | 1.7% | — |
| CVE-2022-30196 | HIGH 8.2 | microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability | 1.7% | — |
| CVE-2022-35759 | MED 6.5 | microsoft windows_10_1507 Windows Local Security Authority (LSA) Denial of Service Vulnerability | 1.7% | — |
| CVE-2020-0926 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- | 1.7% | — |
| CVE-2024-43534 | MED 6.5 | microsoft windows_10_1507 Windows Graphics Component Information Disclosure Vulnerability | 1.7% | — |
| CVE-2023-36736 | MED 4.4 | microsoft identity_linux_broker Microsoft Identity Linux Broker Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2023-36913 | MED 6.5 | microsoft windows_10 Microsoft Message Queuing Information Disclosure Vulnerability | 1.7% | — |
| CVE-2011-3408 | HIGH 7.2 | microsoft windows_7 Csrsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check p | 1.7% | — |
| CVE-2024-21344 | MED 5.9 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 1.7% | — |
| CVE-2023-35367 | CRIT 9.8 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2023-35366 | CRIT 9.8 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2024-30046 | MED 5.9 | microsoft .net Visual Studio Denial of Service Vulnerability | 1.7% | — |
| CVE-2020-0987 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0982, CVE-2020-1005. | 1.7% | — |
| CVE-2000-0298 | HIGH 7.2 | microsoft windows_2000 The unattended installation of Windows 2000 with the OEMPreinstall option sets insecure permissions for the All Users and Default Users directories. | 1.7% | — |
| CVE-2022-26817 | MED 6.6 | microsoft windows_server_2012 Windows DNS Server Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2022-26814 | MED 6.6 | microsoft windows_server_2012 Windows DNS Server Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2012-0008 | MED 6.9 | microsoft visual_studio Untrusted search path vulnerability in Microsoft Visual Studio 2008 SP1, 2010, and 2010 SP1 allows local users to gain privileges via a Trojan horse add-in in an unspecified directory, aka "Visual Studio Add-In Vulnerability." | 1.7% | — |
| CVE-2025-21250 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2025-21246 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2025-21245 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2025-21244 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2025-21243 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.7% | — |