56.652 CVE tracked
776 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-0642 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0624. | 1.5% | — |
| CVE-2023-21745 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 1.5% | — |
| CVE-2022-30203 | HIGH 7.4 | microsoft windows_10 Windows Boot Manager Security Feature Bypass Vulnerability | 1.5% | — |
| CVE-2016-0197 | HIGH 7.8 | microsoft windows_10 dxgkrnl.sys in the DirectX Graphics kernel subsystem in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows | 1.5% | — |
| CVE-2024-43533 | HIGH 8.8 | microsoft windows_11_21h2 Remote Desktop Client Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2023-24856 | HIGH 7.5 | microsoft windows_10 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 1.5% | — |
| CVE-2017-8704 | MED 5.3 | microsoft windows_10 The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows a denial of service vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Denial of Service Vulnerab | 1.5% | — |
| CVE-2016-0057 | HIGH 7.8 | microsoft office Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 does not properly sign an unspecified binary file, which allows local users to gain privileges via a Trojan horse file with a crafted signature, aka "Microsoft Office Security Feature Bypass Vulnerability | 1.5% | — |
| CVE-2024-21303 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.5% | — |
| CVE-1999-0794 | MED 4.6 | microsoft excel Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file. | 1.5% | — |
| CVE-2023-36427 | HIGH 7.0 | microsoft windows_10_1809 Windows Hyper-V Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2016-3305 | HIGH 7.8 | microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 mishandles session objects, which allows local users to hijack sessi | 1.5% | — |
| CVE-2020-0821 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1007. | 1.5% | — |
| CVE-2000-0420 | HIGH 7.2 | microsoft windows_2000 The default configuration of SYSKEY in Windows 2000 stores the startup key in the registry, which could allow an attacker tor ecover it and use it to decrypt Encrypted File System (EFS) data. | 1.5% | — |
| CVE-2025-21248 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2025-21241 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2025-21239 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2024-30029 | HIGH 7.5 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2024-30015 | HIGH 7.5 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2024-30014 | HIGH 7.5 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2020-1107 | MED 5.4 | microsoft sharepoint_enterprise_server A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an | 1.5% | — |
| CVE-2020-1063 | MED 5.4 | microsoft dynamics_365 A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially cr | 1.5% | — |
| CVE-2024-38061 | HIGH 7.5 | microsoft windows_10_1507 DCOM Remote Cross-Session Activation Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2023-32024 | LOW 3.0 | microsoft power_apps Microsoft Power Apps Spoofing Vulnerability | 1.5% | — |
| CVE-2022-44713 | HIGH 7.5 | microsoft office Microsoft Outlook for Mac Spoofing Vulnerability | 1.5% | — |