IT
56.664 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-43517 HIGH 8.8 microsoft windows_10_1507 Microsoft ActiveX Data Objects Remote Code Execution Vulnerability 1.3%
CVE-2024-29066 HIGH 7.2 microsoft windows_server_2008 Windows Distributed File System (DFS) Remote Code Execution Vulnerability 1.3%
CVE-2010-0484 MED 6.8 microsoft windows_2000 The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 "do not properly validate changes in certain kernel objects," which allows local users to execute arbi 1.3%
CVE-1999-1370 HIGH 7.2 microsoft internet_explorer The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prev 1.3%
CVE-2005-0921 MED 4.6 microsoft outlook_connector Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy. 1.3%
CVE-2023-32042 MED 6.5 microsoft windows_10_1507 OLE Automation Information Disclosure Vulnerability 1.3%
CVE-2024-43583 HIGH 7.8 microsoft windows_10_1507 Winlogon Elevation of Privilege Vulnerability 1.3%
CVE-2026-21243 HIGH 7.5 microsoft windows_server_2019 Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. 1.3%
CVE-2026-20846 HIGH 7.5 microsoft windows_10_1607 Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network. 1.3%
CVE-2003-1482 MED 4.6 microsoft mn-500_wireless_base_station The backup configuration file for Microsoft MN-500 wireless base station stores administrative passwords in plaintext, which allows local users to gain access. 1.3%
CVE-2025-55227 HIGH 8.8 microsoft sql_server_2016 Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 1.3%
CVE-2024-21403 CRIT 9.0 microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability 1.3%
CVE-2019-1282 MED 5.5 microsoft windows_10 An information disclosure exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle sandbox checks, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'. 1.3%
CVE-2019-1274 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. 1.3%
CVE-2025-29807 HIGH 8.7 microsoft dataverse Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. 1.3%
CVE-2022-35796 HIGH 7.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.3%
CVE-2024-20679 MED 6.5 microsoft azure_stack_hub Azure Stack Hub Spoofing Vulnerability 1.3%
CVE-2019-0632 HIGH 7.8 microsoft powershell_core A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0627, CVE-2019-0631. 1.3%
CVE-2019-0631 HIGH 7.8 microsoft powershell_core A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0627, CVE-2019-0632. 1.3%
CVE-2021-36959 MED 5.5 microsoft windows_10 Windows Authenticode Spoofing Vulnerability 1.3%
CVE-2018-8142 MED 5.3 microsoft windows_10 A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1035. 1.3%
CVE-2018-1035 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows 10, Windows 10 Servers. 1.3%
CVE-2024-43581 HIGH 7.1 microsoft windows_10_1809 Microsoft OpenSSH for Windows Remote Code Execution Vulnerability 1.3%
CVE-2019-1423 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the StartTileData.dll handles file creation in protected locations, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1420, CVE-2019-1422. 1.3%
CVE-2024-43608 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.3%