56.625 CVE tracked
776 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-8650 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoi | 1.6% | — |
| CVE-2024-49086 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-49085 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2020-1580 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra | 1.6% | — |
| CVE-2019-0963 | MED 5.4 | microsoft sharepoint_foundation A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. | 1.6% | — |
| CVE-2012-0149 | HIGH 7.2 | microsoft windows_server_2003 afd.sys in the Ancillary Function Driver in Microsoft Windows Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of P | 1.6% | — |
| CVE-2018-0810 | MED 4.7 | microsoft windows_7 The Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2, and Windows Server 2012 allows an information disclosure vulnerability due to the way memory is initialized, aka "Windows Kernel Information Disclosure Vulnerability". This CVE is unique from | 1.6% | — |
| CVE-2018-0757 | MED 4.7 | microsoft windows_10 The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulne | 1.6% | — |
| CVE-2023-36718 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Virtual Trusted Platform Module Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2019-0951 | MED 5.4 | microsoft sharepoint_foundation A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949, CVE-2019- | 1.6% | — |
| CVE-2024-35267 | HIGH 7.6 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 1.6% | — |
| CVE-2024-35266 | HIGH 7.6 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 1.6% | — |
| CVE-2025-21178 | HIGH 8.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2019-1137 | MED 5.4 | microsoft exchange_server A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'. | 1.6% | — |
| CVE-2018-8309 | MED 5.5 | microsoft windows_10 A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Wi | 1.6% | — |
| CVE-2025-24051 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1.6% | — |
| CVE-2020-17063 | MED 6.8 | microsoft 365_apps Microsoft Office Online Spoofing Vulnerability | 1.6% | — |
| CVE-2020-1340 | MED 5.4 | microsoft nugetgallery A spoofing vulnerability exists when the NuGetGallery does not properly sanitize input on package metadata values, aka 'NuGetGallery Spoofing Vulnerability'. | 1.6% | — |
| CVE-2016-0135 | HIGH 8.4 | microsoft windows_10 The Secondary Logon Service in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevation of Privilege Vulnerability." | 1.6% | — |
| CVE-2012-1864 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver | 1.6% | — |
| CVE-2022-23258 | MED 4.3 | microsoft edge Microsoft Edge for Android Spoofing Vulnerability | 1.6% | — |
| CVE-2024-21353 | HIGH 8.8 | microsoft windows_server_2022_23h2 Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2022-23261 | MED 5.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Tampering Vulnerability | 1.6% | — |
| CVE-2020-0663 | MED 4.2 | microsoft edge An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacke | 1.6% | — |
| CVE-2011-0043 | HIGH 7.2 | microsoft windows_2003_server Kerberos in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 supports weak hashing algorithms, which allows local users to gain privileges by operating a service that sends crafted service tickets, as demonstrated by the CRC32 algorithm, aka "Kerberos Unke | 1.6% | — |