IT
56.652 CVE tracked
776 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-0642 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0624. 1.5%
CVE-2023-21745 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability 1.5%
CVE-2022-30203 HIGH 7.4 microsoft windows_10 Windows Boot Manager Security Feature Bypass Vulnerability 1.5%
CVE-2016-0197 HIGH 7.8 microsoft windows_10 dxgkrnl.sys in the DirectX Graphics kernel subsystem in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows 1.5%
CVE-2024-43533 HIGH 8.8 microsoft windows_11_21h2 Remote Desktop Client Remote Code Execution Vulnerability 1.5%
CVE-2023-24856 HIGH 7.5 microsoft windows_10 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 1.5%
CVE-2017-8704 MED 5.3 microsoft windows_10 The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows a denial of service vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Denial of Service Vulnerab 1.5%
CVE-2016-0057 HIGH 7.8 microsoft office Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 does not properly sign an unspecified binary file, which allows local users to gain privileges via a Trojan horse file with a crafted signature, aka "Microsoft Office Security Feature Bypass Vulnerability 1.5%
CVE-2024-21303 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.5%
CVE-1999-0794 MED 4.6 microsoft excel Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file. 1.5%
CVE-2023-36427 HIGH 7.0 microsoft windows_10_1809 Windows Hyper-V Elevation of Privilege Vulnerability 1.5%
CVE-2016-3305 HIGH 7.8 microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 mishandles session objects, which allows local users to hijack sessi 1.5%
CVE-2020-0821 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1007. 1.5%
CVE-2000-0420 HIGH 7.2 microsoft windows_2000 The default configuration of SYSKEY in Windows 2000 stores the startup key in the registry, which could allow an attacker tor ecover it and use it to decrypt Encrypted File System (EFS) data. 1.5%
CVE-2025-21248 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.5%
CVE-2025-21241 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.5%
CVE-2025-21239 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.5%
CVE-2024-30029 HIGH 7.5 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.5%
CVE-2024-30015 HIGH 7.5 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.5%
CVE-2024-30014 HIGH 7.5 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.5%
CVE-2020-1107 MED 5.4 microsoft sharepoint_enterprise_server A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an 1.5%
CVE-2020-1063 MED 5.4 microsoft dynamics_365 A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially cr 1.5%
CVE-2024-38061 HIGH 7.5 microsoft windows_10_1507 DCOM Remote Cross-Session Activation Elevation of Privilege Vulnerability 1.5%
CVE-2023-32024 LOW 3.0 microsoft power_apps Microsoft Power Apps Spoofing Vulnerability 1.5%
CVE-2022-44713 HIGH 7.5 microsoft office Microsoft Outlook for Mac Spoofing Vulnerability 1.5%