IT
56.625 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2015-1702 MED 6.9 microsoft windows_7 The Service Control Manager (SCM) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain imper 1.6%
CVE-2020-1451 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- 1.6%
CVE-2020-1450 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- 1.6%
CVE-2019-1054 MED 5.0 microsoft edge A security feature bypass vulnerability exists in Edge that allows for bypassing Mark of the Web Tagging (MOTW). Failing to set the MOTW means that a large number of Microsoft security technologies are bypassed. In a web-based attack scenario, an attacker coul 1.6%
CVE-2021-1684 MED 5.0 microsoft windows_10 Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software 1.6%
CVE-2020-0917 MED 6.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0918. 1.6%
CVE-2024-43635 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.6%
CVE-2024-43628 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.6%
CVE-2024-43627 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.6%
CVE-2024-30013 HIGH 8.8 microsoft windows_10_1607 Windows MultiPoint Services Remote Code Execution Vulnerability 1.6%
CVE-2024-48996 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1.6%
CVE-2024-48995 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1.6%
CVE-2024-48994 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1.6%
CVE-2024-48993 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1.6%
CVE-2024-43462 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1.6%
CVE-2024-43459 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1.6%
CVE-2024-38255 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1.6%
CVE-2024-38180 HIGH 8.8 microsoft windows_10_1507 Windows SmartScreen Security Feature Bypass Vulnerability 1.6%
CVE-2024-38154 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.6%
CVE-2008-0322 HIGH 7.8 microsoft windows_xp The I2O Utility Filter driver (i2omgmt.sys) 5.1.2600.2180 for Microsoft Windows XP sets Everyone/Write permissions for the "\\.\I2OExc" device interface, which allows local users to gain privileges. NOTE: this issue can be leveraged to overwrite arbitrary mem 1.6%
CVE-2021-41371 MED 4.4 microsoft windows_10 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability 1.6%
CVE-2019-1399 MED 6.2 microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-071 1.6%
CVE-2026-21536 CRIT 9.8 microsoft devices_pricing_program Microsoft Devices Pricing Program Remote Code Execution Vulnerability 1.6%
CVE-2025-21364 HIGH 7.8 microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability 1.6%
CVE-2021-28315 HIGH 7.8 microsoft windows_10 Windows Media Video Decoder Remote Code Execution Vulnerability 1.6%