56.625 CVE tracked
776 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-26224 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-26223 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2021-31184 | MED 5.5 | microsoft windows_10 Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability | 1.6% | — |
| CVE-2019-1375 | MED 5.4 | microsoft dynamics_365 A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. | 1.6% | — |
| CVE-2019-0876 | MED 5.5 | microsoft open_enclave_software_development_kit An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'. | 1.6% | — |
| CVE-2024-21302 | MED 6.7 | microsoft windows_10_1507 Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to | 1.6% | — |
| CVE-2023-35384 | MED 5.4 | microsoft windows_10_1507 Windows HTML Platforms Security Feature Bypass Vulnerability | 1.6% | — |
| CVE-2023-24936 | HIGH 7.5 | microsoft .net .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | 1.6% | — |
| CVE-2022-23256 | HIGH 8.1 | microsoft azure_data_explorer Azure Data Explorer Spoofing Vulnerability | 1.6% | — |
| CVE-2025-27472 | MED 5.4 | microsoft windows_10_1507 Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network. | 1.6% | — |
| CVE-2023-35321 | MED 6.5 | microsoft windows_server_2008 Windows Deployment Services Denial of Service Vulnerability | 1.6% | — |
| CVE-2015-6126 | HIGH 7.2 | microsoft windows_10 Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 | 1.6% | — |
| CVE-1999-0701 | HIGH 7.2 | microsoft windows_nt After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password. | 1.6% | — |
| CVE-1999-0839 | HIGH 7.2 | microsoft ie Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled. | 1.6% | — |
| CVE-2025-55241 | CRIT 10.0 | microsoft entra_id Azure Entra ID Elevation of Privilege Vulnerability | 1.6% | — |
| CVE-2024-47083 | HIGH 7.5 | microsoft power_platform_terraform_provider Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior to 3.0.0 have an issue in the Power Platform Terraform Provider where sensitive information, specifically the `client_secret` used in the s | 1.6% | — |
| CVE-2024-38049 | MED 6.6 | microsoft windows_10_1507 Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37333 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37330 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37329 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37328 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37324 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37321 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37320 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-35256 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |