IT
56.601 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2017-8530 MED 5.4 microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when Microsoft Edge does not properly enforce same-origin policies, aka "Microsoft Edge Sec 1.7%
CVE-2015-2428 LOW 2.1 microsoft windows_7 Object Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels during interaction with obje 1.7%
CVE-1999-0546 MED 4.6 microsoft windows_nt The Windows NT guest account is enabled. 1.7%
CVE-2024-21375 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.7%
CVE-2019-0778 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. 1.7%
CVE-2024-49068 HIGH 8.2 microsoft sharepoint_server Microsoft SharePoint Elevation of Privilege Vulnerability 1.7%
CVE-2013-3862 MED 6.9 microsoft windows_7 Double free vulnerability in Microsoft Windows 7 and Server 2008 R2 SP1 allows local users to gain privileges via a crafted service description that is not properly handled by services.exe in the Service Control Manager (SCM), aka "Service Control Manager Doub 1.7%
CVE-2013-3859 MED 6.9 microsoft office Microsoft Pinyin IME 2010, when used in conjunction with Microsoft Office 2010 SP1, does not properly restrict configuration options, which allows local users to gain privileges by starting Internet Explorer from the IME toolbar, aka "Chinese IME Vulnerability 1.7%
CVE-2001-1570 LOW 2.1 microsoft windows_xp Windows XP with fast user switching and account lockout enabled allows local users to deny user account access by setting the fast user switch to the same user (self) multiple times, which causes other accounts to be locked out. 1.7%
CVE-2021-1683 MED 5.0 microsoft windows_10 Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software 1.7%
CVE-2023-33140 MED 6.5 microsoft onenote Microsoft OneNote Spoofing Vulnerability 1.6%
CVE-2020-0903 MED 5.4 microsoft exchange_server A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'. 1.6%
CVE-2019-0685 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0803, CVE-2019-0859. 1.6%
CVE-2026-35416 HIGH 7.0 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 1.6%
CVE-2020-17048 MED 4.2 microsoft chakracore Chakra Scripting Engine Memory Corruption Vulnerability 1.6%
CVE-2025-21242 MED 5.9 microsoft windows_10_1507 Windows Kerberos Information Disclosure Vulnerability 1.6%
CVE-2024-37334 HIGH 8.8 microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability 1.6%
CVE-2012-1894 MED 6.9 microsoft office Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, which allows local users to gain privileges by placing a Trojan horse executable file in one of these directori 1.6%
CVE-2025-27474 MED 6.5 microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.6%
CVE-2025-26672 MED 6.5 microsoft windows_10_1507 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.6%
CVE-2025-26667 MED 6.5 microsoft windows_server_2008 Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.6%
CVE-2025-26664 MED 6.5 microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.6%
CVE-2024-21368 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.6%
CVE-2024-21361 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.6%
CVE-2024-21359 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.6%