56.663 CVE tracked
776 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2010-1896 | HIGH 8.4 | microsoft windows_2003_server The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 do not properly validate user-mode input passed to kernel mode, which allows local users | 1.4% | — |
| CVE-2025-24045 | HIGH 8.1 | microsoft windows_server_2012 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1.4% | — |
| CVE-2024-43589 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2016-7275 | HIGH 7.8 | microsoft office Microsoft Office 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vulnerability." | 1.4% | — |
| CVE-2018-8132 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CV | 1.4% | — |
| CVE-2018-8129 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CV | 1.4% | — |
| CVE-2018-0958 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CV | 1.4% | — |
| CVE-2025-21306 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2025-21305 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2025-21303 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2025-21302 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2025-21252 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-43598 | HIGH 8.1 | microsoft lightgbm LightGBM Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2025-59259 | MED 6.5 | microsoft windows_10_1507 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. | 1.4% | — |
| CVE-2025-59257 | MED 6.5 | microsoft windows_11_24h2 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. | 1.4% | — |
| CVE-2024-43519 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2018-8204 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server | 1.4% | — |
| CVE-2018-8200 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server | 1.4% | — |
| CVE-2025-29960 | MED 6.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.4% | — |
| CVE-2025-29959 | MED 6.5 | microsoft windows_10_1507 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.4% | — |
| CVE-2021-26421 | MED 6.5 | microsoft lync_server Skype for Business and Lync Spoofing Vulnerability | 1.4% | — |
| CVE-2017-8746 | MED 5.3 | microsoft windows_10 Windows Device Guard in Windows 10 1607, 1703, and Windows Server 2016 allows A security feature bypass vulnerability due to how PowerShell exposes functions and processes user supplied code, aka "Device Guard Security Feature Bypass Vulnerability". | 1.4% | — |
| CVE-2025-27487 | HIGH 8.0 | microsoft remote_desktop_client Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network. | 1.4% | — |
| CVE-1999-1358 | MED 4.6 | microsoft windows_2000 When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the po | 1.4% | — |
| CVE-2025-29805 | HIGH 7.5 | microsoft outlook Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network. | 1.4% | — |