IT
56.592 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-33072 HIGH 8.1 microsoft msagsfeedback.azurewebsites.net Improper access control in Azure allows an unauthorized attacker to disclose information over a network. 1.7%
CVE-2025-29813 CRIT 10.0 microsoft azure_devops Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. 1.7%
CVE-2024-38202 HIGH 7.3 microsoft windows_10_1607 Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization 1.7%
CVE-2024-38088 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.7%
CVE-2024-38087 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.7%
CVE-2024-49091 HIGH 7.2 microsoft windows_server_2012 Windows Domain Name Service Remote Code Execution Vulnerability 1.7%
CVE-2011-0089 HIGH 7.2 microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain pri 1.7%
CVE-2011-0086 HIGH 7.2 microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain pri 1.7%
CVE-2024-37336 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.7%
CVE-2019-1203 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra 1.7%
CVE-2018-8419 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008 1.7%
CVE-2015-2364 HIGH 7.2 microsoft windows_2003_server The graphics component in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privil 1.7%
CVE-2015-2363 HIGH 7.2 microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012, and Windows RT allows local users to gain privileges via a 1.7%
CVE-2025-24056 HIGH 8.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network. 1.7%
CVE-2024-43455 HIGH 8.8 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Spoofing Vulnerability 1.7%
CVE-2023-36396 HIGH 7.8 microsoft windows_11_22h2 Windows Compressed Folder Remote Code Execution Vulnerability 1.7%
CVE-2023-23392 CRIT 9.8 microsoft windows_11_21h2 HTTP Protocol Stack Remote Code Execution Vulnerability 1.7%
CVE-2015-2552 HIGH 7.2 microsoft windows_10 The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows physically proximate attackers to bypass the Trusted Boot protection mechanism, and consequently interfere with the integrity of cod 1.7%
CVE-2020-16945 HIGH 8.7 microsoft sharepoint_enterprise_server <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially 1.7%
CVE-2020-0884 LOW 3.7 microsoft visual_studio_2017 A spoofing vulnerability exists in Microsoft Visual Studio as it includes a reply URL that is not secured by SSL, aka 'Microsoft Visual Studio Spoofing Vulnerability'. 1.7%
CVE-2008-3003 MED 6.6 microsoft office Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain a 1.7%
CVE-2006-3443 HIGH 7.2 microsoft windows_2000 Untrusted search path vulnerability in Winlogon in Microsoft Windows 2000 SP4, when SafeDllSearchMode is disabled, allows local users to gain privileges via a malicious DLL in the UserProfile directory, aka "User Profile Elevation of Privilege Vulnerability." 1.7%
CVE-2001-0501 MED 4.6 microsoft word Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner. 1.7%
CVE-2022-38008 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 1.7%
CVE-2020-1105 MED 5.4 microsoft sharepoint_enterprise_server A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an 1.7%