IT
56.663 CVE tracked
776 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2010-1896 HIGH 8.4 microsoft windows_2003_server The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 do not properly validate user-mode input passed to kernel mode, which allows local users 1.4%
CVE-2025-24045 HIGH 8.1 microsoft windows_server_2012 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. 1.4%
CVE-2024-43589 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.4%
CVE-2016-7275 HIGH 7.8 microsoft office Microsoft Office 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vulnerability." 1.4%
CVE-2018-8132 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CV 1.4%
CVE-2018-8129 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CV 1.4%
CVE-2018-0958 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CV 1.4%
CVE-2025-21306 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.4%
CVE-2025-21305 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.4%
CVE-2025-21303 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.4%
CVE-2025-21302 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.4%
CVE-2025-21252 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.4%
CVE-2024-43598 HIGH 8.1 microsoft lightgbm LightGBM Remote Code Execution Vulnerability 1.4%
CVE-2025-59259 MED 6.5 microsoft windows_10_1507 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. 1.4%
CVE-2025-59257 MED 6.5 microsoft windows_11_24h2 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. 1.4%
CVE-2024-43519 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.4%
CVE-2018-8204 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 1.4%
CVE-2018-8200 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 1.4%
CVE-2025-29960 MED 6.5 microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.4%
CVE-2025-29959 MED 6.5 microsoft windows_10_1507 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.4%
CVE-2021-26421 MED 6.5 microsoft lync_server Skype for Business and Lync Spoofing Vulnerability 1.4%
CVE-2017-8746 MED 5.3 microsoft windows_10 Windows Device Guard in Windows 10 1607, 1703, and Windows Server 2016 allows A security feature bypass vulnerability due to how PowerShell exposes functions and processes user supplied code, aka "Device Guard Security Feature Bypass Vulnerability". 1.4%
CVE-2025-27487 HIGH 8.0 microsoft remote_desktop_client Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network. 1.4%
CVE-1999-1358 MED 4.6 microsoft windows_2000 When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the po 1.4%
CVE-2025-29805 HIGH 7.5 microsoft outlook Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network. 1.4%