56.662 CVE tracked
776 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2009-0320 | MED 4.0 | microsoft windows_server_2003 Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estim | 1.4% | — |
| CVE-2019-1460 | MED 4.6 | microsoft outlook A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka 'Outlook for Android Spoofing Vulnerability'. | 1.4% | — |
| CVE-2024-37341 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2011-1234 | HIGH 7.2 | microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain | 1.4% | — |
| CVE-2019-1325 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists in the Windows redirected drive buffering system (rdbss.sys) when the operating system improperly handles specific local calls within Windows 7 for 32-bit systems, aka 'Windows Redirected Drive Buffering System El | 1.4% | — |
| CVE-2025-53805 | HIGH 7.5 | microsoft windows_11_22h2 Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network. | 1.4% | — |
| CVE-2023-36796 | HIGH 7.8 | microsoft .net Visual Studio Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-36794 | HIGH 7.8 | microsoft .net Visual Studio Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-36793 | HIGH 7.8 | microsoft .net Visual Studio Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-36792 | HIGH 7.8 | microsoft .net Visual Studio Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-28254 | HIGH 7.2 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2021-27077 | HIGH 7.8 | microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2020-1417 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, | 1.4% | — |
| CVE-2019-0620 | HIGH 7.6 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a | 1.4% | — |
| CVE-2012-0157 | HIGH 8.4 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle window messaging, which allows local users to ga | 1.4% | — |
| CVE-2023-35302 | HIGH 8.8 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-43447 | HIGH 8.1 | microsoft windows_server_2022 Windows SMBv3 Server Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2022-24767 | HIGH 7.8 | git_for_windows_project git_for_windows GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account. | 1.4% | — |
| CVE-2017-8716 | MED 5.3 | microsoft windows_10 Windows Control Flow Guard in Microsoft Windows 10 Version 1703 allows an attacker to run a specially crafted application to bypass Control Flow Guard, due to the way that Control Flow Guard handles objects in memory, aka "Windows Security Feature Bypass Vulne | 1.4% | — |
| CVE-2025-21297 | HIGH 8.1 | microsoft windows_server_2008 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-36013 | MED 6.5 | microsoft powershell PowerShell Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-0837 | MED 5.0 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when Active Directory Federation Services (ADFS) improperly handles multi-factor authentication requests. An attacker who successfully exploited this vulnerability could bypass some, but not all, of the authent | 1.4% | — |
| CVE-2011-1242 | HIGH 7.2 | microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain | 1.4% | — |
| CVE-2011-1241 | HIGH 7.2 | microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain | 1.4% | — |
| CVE-2011-1240 | HIGH 7.2 | microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain | 1.4% | — |