56.625 CVE tracked
776 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2000-0277 | HIGH 7.2 | microsoft excel Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability. | 1.6% | — |
| CVE-2025-21225 | MED 5.9 | microsoft windows_server_2016 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | 1.6% | — |
| CVE-2024-30056 | HIGH 7.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 1.6% | — |
| CVE-2020-16940 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context.</p> <p>To exp | 1.6% | — |
| CVE-2020-0694 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- | 1.6% | — |
| CVE-2019-1261 | HIGH 8.8 | microsoft sharepoint_enterprise_server A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF).To exploit this vulnerability, an attacker would need to create a page specifically designed t | 1.6% | — |
| CVE-2013-1293 | MED 6.9 | microsoft windows_7 The NTFS kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted applica | 1.6% | — |
| CVE-2011-1282 | HIGH 8.4 | microsoft windows_2003_server The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly initial | 1.6% | — |
| CVE-2026-27908 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally. | 1.6% | — |
| CVE-2023-21762 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 1.6% | — |
| CVE-2025-33057 | MED 6.5 | microsoft windows_10_1507 Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network. | 1.5% | — |
| CVE-2024-21369 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2022-35830 | HIGH 8.1 | microsoft windows_server_2008 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2007-2229 | HIGH 7.2 | microsoft windows_vista Microsoft Windows Vista uses insecure default permissions for unspecified "local user information data stores" in the registry and the file system, which allows local users to obtain sensitive information such as administrative passwords, aka "Permissive User | 1.5% | — |
| CVE-2026-65788 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 1.5% | — |
| CVE-2026-61929 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 1.5% | — |
| CVE-2023-21563 | MED 6.8 | microsoft windows_10_1607 BitLocker Security Feature Bypass Vulnerability | 1.5% | — |
| CVE-2019-1273 | MED 5.4 | microsoft windows_10 A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize certain error messages, aka 'Active Directory Federation Services XSS Vulnerability'. | 1.5% | — |
| CVE-1999-0578 | MED 4.6 | microsoft windows_nt A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys. | 1.5% | — |
| CVE-2022-41062 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2020-17010 | HIGH 7.8 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2019-1362 | HIGH 7.8 | microsoft windows_7 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1364. | 1.5% | — |
| CVE-2020-0795 | MED 5.4 | microsoft business_productivity_servers This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePo | 1.5% | — |
| CVE-2009-2513 | HIGH 7.2 | microsoft windows_2000 The Graphics Device Interface (GDI) in win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain | 1.5% | — |
| CVE-2009-1127 | HIGH 7.2 | microsoft windows_2000 win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not correctly validate an argument to an unspecified system call, which allows local users to gain privileges v | 1.5% | — |