56.592 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-21240 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2025-21238 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2025-21237 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2025-21236 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2025-21233 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2024-38143 | MED 4.2 | microsoft windows_10_1507 Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2022-26830 | HIGH 7.5 | microsoft windows_11 DiskUsage.exe Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2015-1681 | LOW 1.9 | microsoft windows_7 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to cause a denial of service via a crafted .msc file, aka "Microsoft Manageme | 1.7% | — |
| CVE-2026-59124 | CRIT 9.8 | microsoft windows_app Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. | 1.7% | — |
| CVE-2022-41037 | HIGH 8.8 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2022-41036 | HIGH 8.8 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2020-1566 | MED 4.2 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, | 1.7% | — |
| CVE-2017-8703 | MED 5.5 | microsoft windows_10 The Microsoft Windows Subsystem for Linux on Microsoft Windows 10 1703 allows a denial of service vulnerability when it improperly handles objects in memory, aka "Windows Subsystem for Linux Denial of Service Vulnerability". | 1.7% | — |
| CVE-2017-0218 | MED 5.3 | microsoft windows_10 Microsoft Windows 10 Gold, Windows 10 1511, Windows 10 1607, and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, | 1.7% | — |
| CVE-2022-35767 | HIGH 8.1 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2022-35766 | HIGH 8.1 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2018-8486 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Wind | 1.7% | — |
| CVE-2017-0255 | MED 5.4 | microsoft sharepoint_foundation Microsoft SharePoint Foundation 2013 SP1 allows an elevation of privilege vulnerability when it does not properly sanitize a specially crafted web request, aka "Microsoft SharePoint XSS Vulnerability". | 1.7% | — |
| CVE-2017-0184 | MED 5.4 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V running on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-017 | 1.7% | — |
| CVE-2022-35747 | MED 5.9 | microsoft windows_10_1507 Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability | 1.7% | — |
| CVE-2020-0615 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'. This CVE ID is unique from | 1.7% | — |
| CVE-2015-0078 | HIGH 7.2 | microsoft windows_8 win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly validate the token of a calling thread, which allows local users to gain privileges via a crafted applicat | 1.7% | — |
| CVE-2010-0237 | MED 6.9 | microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows local users to gain privileges by creating a symbolic link from an untrusted registry hive to a trusted registry hive, aka "Windows Kernel Symbolic Link Creation Vulnerability." | 1.7% | — |
| CVE-2008-5044 | MED 4.0 | microsoft windows_server_2003 Race condition in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (crash or hang) via a multi-threaded application that makes many calls to UnhookWindowsHookEx while certain other desktop activity is occurring. | 1.7% | — |
| CVE-2006-1475 | LOW 2.1 | microsoft windows_xp Windows Firewall in Microsoft Windows XP SP2 does not produce application alerts when an application is executed using the NTFS Alternate Data Streams (ADS) filename:stream syntax, which might allow local users to launch a Trojan horse attack in which the vict | 1.7% | — |