IT
56.625 CVE tracked
776 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2009-2515 HIGH 7.2 microsoft windows_2000 Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application that triggers an incorrect truncation of a 64 1.5%
CVE-2024-45383 MED 5.0 microsoft high_definition_audio_bus_driver A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can issue multiple IRP Complete requests which leads to a loc 1.5%
CVE-2008-2143 LOW 1.9 microsoft outlook_web_access Unspecified versions of Microsoft Outlook Web Access (OWA) use the Cache-Control: no-cache HTTP directive instead of no-store, which might cause web browsers that follow RFC-2616 to cache sensitive information. 1.5%
CVE-2025-54100 HIGH 7.8 microsoft windows_10_1607 Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally. 1.5%
CVE-2024-30024 HIGH 7.5 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.5%
CVE-2024-30023 HIGH 7.5 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.5%
CVE-2024-30022 HIGH 7.5 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.5%
CVE-2018-8164 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 20 1.5%
CVE-2017-8557 MED 5.5 microsoft windows_10 Windows System Information Console in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability imp 1.5%
CVE-2025-26682 HIGH 7.5 microsoft asp.net_core Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. 1.5%
CVE-2022-37975 HIGH 8.8 microsoft windows_10 Windows Group Policy Elevation of Privilege Vulnerability 1.5%
CVE-2024-49018 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability 1.5%
CVE-2022-33637 MED 6.5 microsoft defender_for_endpoint Microsoft Defender for Endpoint Tampering Vulnerability 1.5%
CVE-2024-43622 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.5%
CVE-2024-43621 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.5%
CVE-2024-43620 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.5%
CVE-2022-44684 MED 6.5 microsoft windows_10_20h2 Windows Local Session Manager (LSM) Denial of Service Vulnerability 1.5%
CVE-2013-1254 MED 4.9 microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently 1.5%
CVE-2017-0077 HIGH 7.8 microsoft windows_10 The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow a local authenticated attacker to execute a specially c 1.5%
CVE-2019-1469 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. 1.5%
CVE-2015-2371 MED 6.9 microsoft windows_2003_server The Windows Installer service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain 1.5%
CVE-2019-1305 MED 5.4 microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'. 1.5%
CVE-2011-1877 HIGH 7.2 microsoft windows_7 Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverag 1.5%
CVE-2025-27477 HIGH 8.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. 1.5%
CVE-2024-21427 HIGH 7.5 microsoft windows_server_2012 Windows Kerberos Security Feature Bypass Vulnerability 1.5%