IT
56.625 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-21449 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.6%
CVE-2024-21425 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.6%
CVE-2024-21331 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.6%
CVE-2024-21317 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.6%
CVE-2024-20701 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.6%
CVE-2025-21295 HIGH 8.1 microsoft windows_10_1507 SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability 1.6%
CVE-2022-38040 HIGH 8.8 microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.6%
CVE-2022-38031 HIGH 8.8 microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.6%
CVE-2022-37982 HIGH 8.8 microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.6%
CVE-2002-1933 HIGH 7.2 microsoft windows_2000_terminal_services The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could allow local users to gain access to the terminal server window. 1.6%
CVE-2022-38048 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 1.6%
CVE-2022-35783 MED 4.4 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 1.6%
CVE-2022-24526 MED 6.1 microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability 1.6%
CVE-2022-24512 MED 6.3 fedoraproject fedora .NET and Visual Studio Remote Code Execution Vulnerability 1.6%
CVE-2021-40460 MED 6.5 microsoft windows_10 Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability 1.6%
CVE-2020-1170 HIGH 7.8 microsoft forefront_endpoint_protection_2010 An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulne 1.6%
CVE-2021-38650 HIGH 7.6 microsoft 365_apps Microsoft Office Spoofing Vulnerability 1.6%
CVE-2012-0179 HIGH 7.2 microsoft windows_7 Double free vulnerability in tcpip.sys in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that binds an IPv6 address to a local interface, aka "TCP/IP Double Free Vulnerabil 1.6%
CVE-2010-3889 HIGH 7.2 microsoft windows Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Microsoft researchers and other researchers. 1.6%
CVE-2003-0350 MED 4.6 microsoft windows_2000 The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager tha 1.6%
CVE-2022-35770 MED 6.5 microsoft windows_10 Windows NTLM Spoofing Vulnerability 1.6%
CVE-2018-8608 MED 5.4 microsoft dynamics_365 A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting 1.6%
CVE-2018-8607 MED 5.4 microsoft dynamics_365 A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting 1.6%
CVE-2018-8606 MED 5.4 microsoft dynamics_365 A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting 1.6%
CVE-2018-8605 MED 5.4 microsoft dynamics_365 A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting 1.6%