IT
56.605 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2012-1865 HIGH 7.2 microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver 1.6%
CVE-2010-2555 MED 6.8 microsoft windows_7 The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the length of strings in the registry, which allows local users to gain privileges or cause a denial of se 1.6%
CVE-2023-38254 MED 6.5 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability 1.6%
CVE-2019-1078 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. An authenticate 1.6%
CVE-2019-0556 MED 5.4 microsoft sharepoint_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoi 1.6%
CVE-2023-32013 MED 5.3 microsoft windows_10_1809 Windows Hyper-V Denial of Service Vulnerability 1.6%
CVE-2014-0300 HIGH 7.2 microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow 1.6%
CVE-2010-0481 MED 5.5 microsoft windows_7 The kernel in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly translate a registry key's virtual path to its real path, which allows local users to cause a denial of service (reboot) via a craf 1.6%
CVE-2015-0075 HIGH 7.2 microsoft windows_2003_server The kernel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 does not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Impersonatio 1.6%
CVE-2021-41337 MED 4.9 microsoft windows_server_2016 Active Directory Security Feature Bypass Vulnerability 1.6%
CVE-2020-1514 MED 5.4 microsoft sharepoint_enterprise_server <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially 1.6%
CVE-2008-2250 HIGH 7.2 microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate window properties sent from a parent window to a child window during creation of a new window, which allows local 1.6%
CVE-2023-28243 HIGH 8.8 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability 1.6%
CVE-2020-1325 MED 5.4 microsoft azure_devops_server Azure DevOps Server and Team Foundation Services Spoofing Vulnerability 1.6%
CVE-2020-1575 MED 5.4 microsoft sharepoint_foundation <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially 1.6%
CVE-2020-16878 MED 5.4 microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially 1.6%
CVE-2020-16871 MED 5.4 microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially 1.6%
CVE-2020-16859 MED 5.4 microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially 1.6%
CVE-2020-16858 MED 5.4 microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially 1.6%
CVE-2017-0178 MED 5.4 microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V running on Windows 10, Windows 10 1511, Windows 10 1607, Windows 8.1, Windows Server 2012 R2, and Windows Server 2016 host server fails to properly validate input from a privileged user on a guest 1.6%
CVE-2026-50476 HIGH 7.8 microsoft windows_10_1607 Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally. 1.6%
CVE-2025-21313 MED 6.5 microsoft windows_11_24h2 Windows Security Account Manager (SAM) Denial of Service Vulnerability 1.6%
CVE-2021-40457 HIGH 7.4 microsoft dynamics_365 Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability 1.6%
CVE-2025-21355 HIGH 8.6 microsoft bing Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network 1.6%
CVE-2024-43591 HIGH 8.7 microsoft azure_command-line_interface Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability 1.6%