IT
56.652 CVE tracked
776 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-38001 MED 6.5 microsoft 365_apps Microsoft Office Spoofing Vulnerability 1.5%
CVE-2020-1318 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- 1.5%
CVE-2020-1297 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- 1.5%
CVE-2020-1183 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- 1.5%
CVE-2020-1177 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- 1.5%
CVE-2023-36766 HIGH 7.8 microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability 1.5%
CVE-2022-21954 MED 6.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.5%
CVE-2007-1973 MED 6.9 microsoft windows_nt Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 allows local users to modify memory and gain privileges via the temporary \Device\PhysicalMemory section handle, a related issue to CVE-2007-1206. 1.5%
CVE-2001-1218 LOW 2.1 microsoft ie Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window. 1.5%
CVE-1999-1364 LOW 2.1 microsoft windows_nt Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext. 1.5%
CVE-1999-1363 LOW 2.1 microsoft windows_nt Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of locks on a file, which exhausts the NonPagedPool. 1.5%
CVE-1999-1360 LOW 2.1 microsoft windows_nt Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle. 1.5%
CVE-2024-38240 HIGH 8.1 microsoft windows_10_1507 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 1.5%
CVE-2023-28268 HIGH 8.1 microsoft windows_server_2008 Netlogon RPC Elevation of Privilege Vulnerability 1.5%
CVE-2023-21708 CRIT 9.8 microsoft windows_10_1507 Remote Procedure Call Runtime Remote Code Execution Vulnerability 1.5%
CVE-2016-3287 MED 4.4 microsoft windows_10 Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Secure Boot protection mechanism by leveraging administrative access to install a crafted policy, aka "Secure Boot Security Fe 1.5%
CVE-2016-0180 HIGH 7.8 microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles symbolic links, which allows local users to gain privileges via 1.5%
CVE-2023-36425 HIGH 8.0 microsoft windows_10_1507 Windows Distributed File System (DFS) Remote Code Execution Vulnerability 1.5%
CVE-2022-37972 HIGH 7.5 microsoft endpoint_configuration_manager Microsoft Endpoint Configuration Manager Spoofing Vulnerability 1.5%
CVE-2020-17113 MED 5.5 microsoft windows_10 Windows Camera Codec Information Disclosure Vulnerability 1.5%
CVE-2019-1163 MED 5.5 microsoft windows_10 A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker who successfully exploited this vulnerability could inject code into a CAB file without invalidating the file's signature. To exploit the vulnerability, an att 1.5%
CVE-2024-21350 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.5%
CVE-2025-29827 CRIT 9.9 microsoft azure_automation Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. 1.5%
CVE-2022-21838 MED 5.5 microsoft windows_10 Windows Cleanup Manager Elevation of Privilege Vulnerability 1.5%
CVE-2001-0350 MED 4.6 microsoft windows_2000 Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program wi 1.5%