IT
56.663 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2017-0056 HIGH 7.8 microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileg 1.4%
CVE-2022-30166 HIGH 7.8 microsoft windows_10 Local Security Authority Subsystem Service Elevation of Privilege Vulnerability 1.4%
CVE-2000-0654 MED 4.6 microsoft sql_server Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability. 1.4%
CVE-2024-38167 MED 6.5 microsoft .net .NET and Visual Studio Information Disclosure Vulnerability 1.4%
CVE-2020-17045 MED 5.5 microsoft windows_10 Windows KernelStream Information Disclosure Vulnerability 1.4%
CVE-2020-17036 MED 5.5 microsoft windows_10 Windows Function Discovery SSDP Provider Information Disclosure Vulnerability 1.4%
CVE-2020-17030 MED 5.5 microsoft windows_10 Windows MSCTF Server Information Disclosure Vulnerability 1.4%
CVE-2020-17029 MED 5.5 microsoft windows_10 Windows Canonical Display Driver Information Disclosure Vulnerability 1.4%
CVE-2020-0874 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'. T 1.4%
CVE-2020-17145 MED 5.4 microsoft azure_devops_server Azure DevOps Server and Team Foundation Services Spoofing Vulnerability 1.4%
CVE-2005-3175 HIGH 7.2 microsoft windows_2000 Microsoft Windows 2000 before Update Rollup 1 for SP4 allows a local administrator to unlock a computer even if it has been locked by a domain administrator, which allows the local administrator to access the session as the domain administrator. 1.4%
CVE-1999-1362 LOW 2.1 microsoft windows_nt Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters. 1.4%
CVE-2026-25181 HIGH 7.5 microsoft windows_10_1607 Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a network. 1.4%
CVE-2023-35322 HIGH 8.8 microsoft windows_server_2008 Windows Deployment Services Remote Code Execution Vulnerability 1.4%
CVE-2023-35300 HIGH 8.8 microsoft windows_10_1507 Remote Procedure Call Runtime Remote Code Execution Vulnerability 1.4%
CVE-2022-41035 MED 5.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 1.4%
CVE-2026-65663 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.4%
CVE-2026-65658 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.4%
CVE-2005-3177 MED 4.6 microsoft windows_2000 CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors do not 1.4%
CVE-2023-38167 HIGH 7.2 microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability 1.4%
CVE-2017-0074 MED 5.4 microsoft windows_10 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of se 1.4%
CVE-2024-21416 HIGH 8.1 microsoft windows_10_1809 Windows TCP/IP Remote Code Execution Vulnerability 1.4%
CVE-2023-21693 MED 5.7 microsoft windows_10 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 1.4%
CVE-2020-8567 MED 4.9 google secret_manager_provider_for_secret_store_csi_driver Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesyst 1.4%
CVE-2021-40484 HIGH 7.6 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 1.4%