56.647 CVE tracked
776 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-0891 | MED 5.4 | microsoft sharepoint_enterprise_server This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePo | 1.5% | — |
| CVE-2004-2730 | MED 4.6 | microsoft psexec Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend | 1.5% | — |
| CVE-2022-21891 | HIGH 7.6 | microsoft dynamics_365_sales Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability | 1.5% | — |
| CVE-2022-21839 | MED 6.1 | microsoft windows_10 Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability | 1.5% | — |
| CVE-2020-1377 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. A locally authenticated atta | 1.5% | — |
| CVE-2024-26231 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2024-26227 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2002-1692 | LOW 3.6 | microsoft windows_95 Buffer overflow in backup utility of Microsoft Windows 95 allows attackers to execute arbitrary code by causing a filename with a long extension to be placed in a folder to be backed up. | 1.5% | — |
| CVE-2025-27491 | HIGH 7.1 | microsoft windows_10_1507 Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network. | 1.5% | — |
| CVE-2025-21380 | HIGH 8.8 | microsoft azure_marketplace Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network. | 1.5% | — |
| CVE-2023-36873 | HIGH 7.4 | microsoft .net_framework .NET Framework Spoofing Vulnerability | 1.5% | — |
| CVE-2025-21203 | MED 6.5 | microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.5% | — |
| CVE-2023-24881 | MED 6.5 | microsoft teams Microsoft Teams Information Disclosure Vulnerability | 1.5% | — |
| CVE-2022-41122 | MED 6.5 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.5% | — |
| CVE-2018-8652 | MED 5.4 | microsoft windows_azure_pack_rollup A Cross-site Scripting (XSS) vulnerability exists when Windows Azure Pack does not properly sanitize user-provided input, aka "Windows Azure Pack Cross Site Scripting Vulnerability." This affects Windows Azure Pack Rollup 13.1. | 1.5% | — |
| CVE-1999-1322 | MED 4.6 | broadcom arcserve_backup The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext. | 1.5% | — |
| CVE-2016-0133 | MED 6.8 | microsoft windows_10 The USB Mass Storage Class driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows physically proximate attackers to execute arb | 1.5% | — |
| CVE-2023-36801 | MED 5.3 | microsoft windows_server_2008 DHCP Server Service Information Disclosure Vulnerability | 1.5% | — |
| CVE-2008-2251 | HIGH 7.2 | microsoft windows_2000 Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that makes system calls within multiple threads, | 1.5% | — |
| CVE-2003-1392 | MED 6.6 | microsoft all_windows CryptoBuddy 1.0 and 1.2 does not use the user-supplied passphrase to encrypt data, which could allow local users to use their own passphrase to decrypt the data. | 1.5% | — |
| CVE-2022-41097 | MED 6.5 | microsoft windows_10 Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability | 1.5% | — |
| CVE-2017-8523 | MED 4.3 | microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when Microsoft Edge fails to correctly apply Same Origin Policy for HTML elements present i | 1.5% | — |
| CVE-2025-26686 | HIGH 7.5 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | 1.5% | — |
| CVE-2024-21313 | MED 5.3 | microsoft windows_10_1507 Windows TCP/IP Information Disclosure Vulnerability | 1.5% | — |
| CVE-2008-3893 | MED 5.5 | microsoft windows_vista Microsoft Bitlocker in Windows Vista before SP1 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer during boot, which allows local users to obtain sensitive information by reading the physical memory locations a | 1.5% | — |