56.663 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1351 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. | 1.4% | — |
| CVE-2009-0082 | HIGH 7.8 | microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted application that triggers unspecified "actions, | 1.4% | — |
| CVE-2021-38639 | HIGH 7.8 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2019-1039 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory. To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this vul | 1.4% | — |
| CVE-2026-20847 | MED 6.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network. | 1.4% | — |
| CVE-2019-1368 | MED 4.6 | microsoft windows_10 A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'. | 1.4% | — |
| CVE-2024-43599 | HIGH 8.8 | microsoft windows_10_1507 Remote Desktop Client Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2023-36014 | HIGH 7.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2019-0864 | MED 5.5 | microsoft .net_framework A denial of service vulnerability exists when .NET Framework improperly handles objects in heap memory, aka '.NET Framework Denial of Service Vulnerability'. | 1.4% | — |
| CVE-2019-0627 | HIGH 7.8 | microsoft powershell_core A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0631, CVE-2019-0632. | 1.3% | — |
| CVE-2011-1231 | HIGH 8.4 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted applica | 1.3% | — |
| CVE-2025-21343 | HIGH 7.5 | microsoft windows_11_22h2 Windows Web Threat Defense User Service Information Disclosure Vulnerability | 1.3% | — |
| CVE-2023-21729 | MED 4.3 | microsoft windows_10_1607 Remote Procedure Call Runtime Information Disclosure Vulnerability | 1.3% | — |
| CVE-2022-38000 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2018-8562 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 20 | 1.3% | — |
| CVE-2018-1039 | HIGH 7.8 | microsoft .net_framework A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, aka ".NET Framework Device Guard Security Feature Bypass Vulnerability." This affects Microsoft .NET Framework 4.7.1, Microsoft .NET Framewor | 1.3% | — |
| CVE-2002-1670 | MED 4.6 | microsoft internet_explorer Microsoft Windows XP Professional upgrade edition overwrites previously installed patches for Internet Explorer 6.0, leaving Internet Explorer unpatched. | 1.3% | — |
| CVE-2023-38158 | LOW 3.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 1.3% | — |
| CVE-2026-63516 | MED 6.5 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 1.3% | — |
| CVE-2023-29373 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-29372 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-29362 | HIGH 8.8 | microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2024-38212 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2011-0671 | HIGH 8.4 | microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain | 1.3% | — |
| CVE-2009-1922 | MED 6.9 | microsoft windows_2000 The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain pr | 1.3% | — |