56.625 CVE tracked
776 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2004-0893 | HIGH 7.2 | microsoft windows_2000 The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Wind | 1.5% | — |
| CVE-2008-4036 | HIGH 8.4 | microsoft windows_server_2003 Integer overflow in Memory Manager in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that triggers an erroneous decrement of a variable, related to | 1.5% | — |
| CVE-2023-24866 | MED 6.5 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 1.5% | — |
| CVE-2023-24865 | MED 6.5 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 1.5% | — |
| CVE-2004-0208 | HIGH 7.2 | microsoft windows_2000 The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is | 1.5% | — |
| CVE-2023-28260 | HIGH 7.8 | microsoft .net .NET DLL Hijacking Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2020-0863 | MED 5.5 | microsoft windows_10 An information vulnerability exists when Windows Connected User Experiences and Telemetry Service improperly discloses file information, aka 'Connected User Experiences and Telemetry Service Information Disclosure Vulnerability'. | 1.5% | — |
| CVE-2025-47171 | MED 6.7 | microsoft 365_apps Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. | 1.5% | — |
| CVE-2013-1284 | MED 4.9 | microsoft windows_8 Race condition in the kernel in Microsoft Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability." | 1.5% | — |
| CVE-2010-3961 | HIGH 7.2 | microsoft windows_7 The Consent User Interface (UI) in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle an unspecified registry-key value, which allows local users with SeImpersonatePrivilege rights to gain privile | 1.5% | — |
| CVE-2007-0210 | HIGH 7.2 | microsoft windows_xp The Window Image Acquisition (WIA) Service in Microsoft Windows XP SP2 allows local users to gain privileges via unspecified vectors involving an "unchecked buffer," probably a buffer overflow. | 1.5% | — |
| CVE-2022-37965 | MED 5.9 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | 1.5% | — |
| CVE-2016-3311 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted appl | 1.5% | — |
| CVE-2024-30104 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2023-35296 | MED 6.5 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 1.5% | — |
| CVE-2026-24302 | HIGH 8.6 | microsoft azure_arc Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | 1.5% | — |
| CVE-2020-1320 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- | 1.5% | — |
| CVE-2020-1298 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- | 1.5% | — |
| CVE-2013-1340 | HIGH 8.4 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, | 1.5% | — |
| CVE-2013-3136 | MED 4.4 | microsoft windows_7 The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensi | 1.5% | — |
| CVE-2000-0771 | LOW 2.1 | microsoft windows_2000 Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability. | 1.5% | — |
| CVE-2022-34708 | MED 5.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 1.5% | — |
| CVE-2013-1274 | MED 4.9 | microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently | 1.5% | — |
| CVE-2013-1273 | MED 4.9 | microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently | 1.5% | — |
| CVE-2013-1272 | MED 4.9 | microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently | 1.5% | — |