56.663 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-0056 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileg | 1.4% | — |
| CVE-2022-30166 | HIGH 7.8 | microsoft windows_10 Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2000-0654 | MED 4.6 | microsoft sql_server Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability. | 1.4% | — |
| CVE-2024-38167 | MED 6.5 | microsoft .net .NET and Visual Studio Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-17045 | MED 5.5 | microsoft windows_10 Windows KernelStream Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-17036 | MED 5.5 | microsoft windows_10 Windows Function Discovery SSDP Provider Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-17030 | MED 5.5 | microsoft windows_10 Windows MSCTF Server Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-17029 | MED 5.5 | microsoft windows_10 Windows Canonical Display Driver Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-0874 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'. T | 1.4% | — |
| CVE-2020-17145 | MED 5.4 | microsoft azure_devops_server Azure DevOps Server and Team Foundation Services Spoofing Vulnerability | 1.4% | — |
| CVE-2005-3175 | HIGH 7.2 | microsoft windows_2000 Microsoft Windows 2000 before Update Rollup 1 for SP4 allows a local administrator to unlock a computer even if it has been locked by a domain administrator, which allows the local administrator to access the session as the domain administrator. | 1.4% | — |
| CVE-1999-1362 | LOW 2.1 | microsoft windows_nt Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters. | 1.4% | — |
| CVE-2026-25181 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a network. | 1.4% | — |
| CVE-2023-35322 | HIGH 8.8 | microsoft windows_server_2008 Windows Deployment Services Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-35300 | HIGH 8.8 | microsoft windows_10_1507 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2022-41035 | MED 5.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1.4% | — |
| CVE-2026-65663 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.4% | — |
| CVE-2026-65658 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.4% | — |
| CVE-2005-3177 | MED 4.6 | microsoft windows_2000 CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors do not | 1.4% | — |
| CVE-2023-38167 | HIGH 7.2 | microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2017-0074 | MED 5.4 | microsoft windows_10 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of se | 1.4% | — |
| CVE-2024-21416 | HIGH 8.1 | microsoft windows_10_1809 Windows TCP/IP Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-21693 | MED 5.7 | microsoft windows_10 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-8567 | MED 4.9 | google secret_manager_provider_for_secret_store_csi_driver Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesyst | 1.4% | — |
| CVE-2021-40484 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.4% | — |