IT
56.625 CVE tracked
776 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-1160 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. 1.6%
CVE-2025-62213 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 1.6%
CVE-2024-43469 HIGH 8.8 microsoft azure_cyclecloud Azure CycleCloud Remote Code Execution Vulnerability 1.6%
CVE-2024-38114 HIGH 8.8 microsoft windows_10_1507 Windows IP Routing Management Snapin Remote Code Execution Vulnerability 1.6%
CVE-2023-21761 HIGH 7.5 microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability 1.6%
CVE-2025-33050 HIGH 7.5 microsoft windows_server_2016 Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. 1.6%
CVE-2020-16864 MED 5.4 microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially 1.6%
CVE-2020-16861 MED 5.4 microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially 1.6%
CVE-2017-0076 MED 5.4 microsoft windows_10 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of se 1.6%
CVE-2026-20875 HIGH 7.5 microsoft windows_10_1607 Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. 1.6%
CVE-2020-0693 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- 1.6%
CVE-2012-0178 HIGH 7.2 microsoft windows_7 Race condition in partmgr.sys in Windows Partition Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that makes multiple simultaneous Plug 1.6%
CVE-2023-36415 HIGH 8.8 microsoft azure_identity_sdk Azure Identity SDK Remote Code Execution Vulnerability 1.6%
CVE-2010-1895 HIGH 7.2 microsoft windows_2003_server The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly perform memory allocation before copying user-mode data to kernel mode, which allows local users to gain privileges via a crafted ap 1.6%
CVE-2026-61348 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 1.6%
CVE-2023-32083 MED 6.5 microsoft windows_server_2016 Microsoft Failover Cluster Information Disclosure Vulnerability 1.6%
CVE-2023-24901 HIGH 7.5 microsoft windows_10_1507 Windows NFS Portmapper Information Disclosure Vulnerability 1.6%
CVE-2023-28247 HIGH 7.5 microsoft windows_server_2012 Windows Network File System Information Disclosure Vulnerability 1.6%
CVE-2019-1412 MED 5.5 microsoft windows_7 An information disclosure vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objects in memory, aka 'OpenType Font Driver Information Disclosure Vulnerability'. 1.6%
CVE-2026-69836 CRIT 10.0 microsoft entra_id Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. 1.6%
CVE-2020-1576 HIGH 8.5 microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the ShareP 1.6%
CVE-2019-1202 MED 4.4 microsoft sharepoint_enterprise_server An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker who successfully exploited the vulnerability could hijack the session of another user. To exploit this vulnerability, the attacker 1.6%
CVE-2010-1891 MED 6.9 microsoft windows_server_2003 The Client/Server Runtime Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2, when a Chinese, Japanese, or Korean locale is enabled, does not properly allocate memory for transactions, which allows local users 1.6%
CVE-2020-15707 MED 5.7 canonical ubuntu_linux Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow 1.6%
CVE-2025-21279 MED 6.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.6%