IT
56.663 CVE tracked
776 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-59247 HIGH 8.8 microsoft azure_playfab Azure PlayFab Elevation of Privilege Vulnerability 1.4%
CVE-2020-0871 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when Windows Network Connections Service fails to properly handle objects in memory, aka 'Windows Network Connections Service Information Disclosure Vulnerability'. 1.4%
CVE-2024-49118 HIGH 8.1 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.4%
CVE-2020-16951 HIGH 8.6 microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the ShareP 1.4%
CVE-2010-1254 MED 6.9 microsoft open_xml_file_format_converter The installation for Microsoft Open XML File Format Converter for Mac sets insecure ACLs for the /Applications folder, which allows local users to execute arbitrary code by replacing the executable with a Trojan Horse, aka "Mac Office Open XML Permissions Vuln 1.4%
CVE-2009-1126 HIGH 7.2 microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate the user-mode input associated with the editing of an unspecified desktop parameter, which allows local users to gain privileges via a crafted application, 1.4%
CVE-2009-1125 HIGH 7.2 microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application 1.4%
CVE-2009-1124 HIGH 7.2 microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate user-mode pointers in unspecified error conditions, which allows local users to gain privileges via a crafted ap 1.4%
CVE-2026-21260 HIGH 7.5 microsoft 365_apps Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. 1.4%
CVE-2023-24858 HIGH 7.5 microsoft windows_10 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 1.4%
CVE-2023-21691 HIGH 7.5 microsoft windows_10_1507 Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulnerability 1.4%
CVE-2018-8233 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 10, Windows 10 Servers. 1.4%
CVE-2022-22040 HIGH 7.3 microsoft windows_10 Internet Information Services Dynamic Compression Module Denial of Service Vulnerability 1.4%
CVE-2018-8612 MED 5.5 microsoft windows_10 A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values, aka "Connected User Experiences and Telemetry Service Denial of Service Vulnerability." This affects Windows Server 2016, 1.4%
CVE-2020-17035 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 1.4%
CVE-2020-0714 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Information Disclosure Vulnerability'. 1.4%
CVE-2017-0099 MED 5.4 microsoft windows_10 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a de 1.4%
CVE-2007-1220 MED 6.2 microsoft xbox_360 The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 does not properly verify the parameters passed to the syscall dispatcher, which allows attackers with physical access to bypass code-signing requirements and execute arbitrary code. 1.4%
CVE-2026-41097 MED 6.7 microsoft windows_10_1809 Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 1.4%
CVE-2025-21314 MED 6.5 microsoft windows_10_1607 Windows SmartScreen Spoofing Vulnerability 1.4%
CVE-2020-16920 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.</p> <p>To exploit the 1.4%
CVE-2016-3349 HIGH 7.8 microsoft windows_10 The kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." 1.4%
CVE-2021-26871 HIGH 7.8 microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability 1.4%
CVE-2020-16992 HIGH 7.5 microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability 1.4%
CVE-2024-27099 CRIT 9.8 microsoft azure_uamqp The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect `AMQP_VALUE` failed state, may cause a double free problem. This may cause a RCE. Update submodule with commit 2ca42b6e4e098af2d17e487814a91d05f6ae4987. 1.4%