IT
56.658 CVE tracked
776 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-1486 MED 6.1 microsoft visual_studio_2019 A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host, aka 'Visual Studio Live Share Spoofing Vulnerability'. 1.5%
CVE-2020-17046 MED 5.5 microsoft windows_10 Windows Error Reporting Denial of Service Vulnerability 1.5%
CVE-2000-0777 HIGH 7.2 microsoft money The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the "Money Password" vulnerability. 1.5%
CVE-2020-1474 HIGH 7.8 microsoft windows_10 An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service improperly discloses contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s syst 1.5%
CVE-2000-0259 HIGH 7.2 microsoft terminal_server The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users. 1.5%
CVE-2025-33056 HIGH 7.5 microsoft windows_10_1507 Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network. 1.5%
CVE-2025-26676 MED 6.5 microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.5%
CVE-2024-21316 MED 6.1 microsoft windows_10_1607 Windows Server Key Distribution Service Security Feature Bypass 1.5%
CVE-2022-41048 HIGH 8.8 microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.5%
CVE-2022-41047 HIGH 8.8 microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.5%
CVE-2022-37978 HIGH 7.5 microsoft windows_10 Windows Active Directory Certificate Services Security Feature Bypass 1.5%
CVE-2020-1049 MED 5.4 microsoft dynamics_365_server A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. This 1.5%
CVE-2020-0754 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0753. 1.5%
CVE-2020-0656 MED 5.4 microsoft dynamics_365 A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. 1.5%
CVE-2025-21332 MED 4.3 microsoft windows_10_1507 MapUrlToZone Security Feature Bypass Vulnerability 1.5%
CVE-2020-1560 HIGH 7.8 microsoft windows_10 A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install program 1.5%
CVE-2018-8337 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists when Windows Subsystem for Linux improperly handles case sensitivity, aka "Windows Subsystem for Linux Security Feature Bypass Vulnerability." This affects Windows 10, Windows 10 Servers. 1.5%
CVE-2021-41378 HIGH 7.8 microsoft windows_10 Windows NTFS Remote Code Execution Vulnerability 1.5%
CVE-2025-21283 MED 6.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.5%
CVE-2018-7249 HIGH 7.0 microsoft windows_7 An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. Two carefully timed calls to IOCTL 0xCA002813 can cause a race condition that leads to 1.5%
CVE-2017-0050 HIGH 7.8 microsoft windows_10 The kernel API in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7; Windows 8; Windows 10 Gold, 1511, and 1607; Windows RT 8.1; Windows Server 2012 Gold and R2; and Windows Server 2016 does not properly enforce permissions, which allo 1.5%
CVE-2011-1229 HIGH 7.2 avaya agent_access win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted applica 1.5%
CVE-2025-47962 HIGH 7.8 microsoft windows_software_development_kit Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally. 1.5%
CVE-2013-1264 MED 4.9 microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently 1.5%
CVE-2013-1263 MED 4.9 microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently 1.5%