56.614 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1227 | MED 5.4 | microsoft sharepoint_enterprise_server <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially | 1.6% | — |
| CVE-2019-1076 | MED 5.4 | microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'. | 1.6% | — |
| CVE-2020-0977 | MED 5.4 | microsoft sharepoint_enterprise_server A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-0972, CVE-2020- | 1.6% | — |
| CVE-2020-0975 | MED 5.4 | microsoft sharepoint_enterprise_server A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-0972, CVE-2020- | 1.6% | — |
| CVE-2020-0972 | MED 5.4 | microsoft sharepoint_enterprise_server A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-0975, CVE-2020- | 1.6% | — |
| CVE-2025-24999 | HIGH 8.8 | microsoft sql_server_2016 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | 1.6% | — |
| CVE-2025-32724 | HIGH 7.5 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | 1.6% | — |
| CVE-2024-38092 | HIGH 8.8 | microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability | 1.6% | — |
| CVE-2024-21308 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2015-0098 | HIGH 7.2 | microsoft windows_7 Task Scheduler in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to gain privileges by triggering application execution by an invalid task, aka "Task Scheduler Elevation of Privilege Vulnerability." | 1.6% | — |
| CVE-2024-38260 | HIGH 8.8 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37340 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37339 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37338 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37335 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-26191 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-26186 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2002-2283 | LOW 1.9 | microsoft windows_xp Microsoft Windows XP with Fast User Switching (FUS) enabled does not remove the "show processes from all users" privilege when the user is removed from the administrator group, which allows that user to view processes of other users. | 1.6% | — |
| CVE-2025-21223 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2021-24073 | MED 6.5 | microsoft lync_server Skype for Business and Lync Spoofing Vulnerability | 1.6% | — |
| CVE-2019-1074 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows where certain folders, with local service privilege, are vulnerable to symbolic link attack. An attacker who successfully exploited this vulnerability could potentially access unauthorized inf | 1.6% | — |
| CVE-2020-16944 | HIGH 8.7 | microsoft sharepoint_enterprise_server <p>This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.</p> <p>An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affec | 1.6% | — |
| CVE-2018-8572 | MED 5.4 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft | 1.6% | — |
| CVE-2018-8547 | MED 5.4 | microsoft windows_10 A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Active Directory Federat | 1.6% | — |
| CVE-2024-38127 | HIGH 7.8 | microsoft windows_10_1507 Windows Hyper-V Elevation of Privilege Vulnerability | 1.6% | — |