IT
56.672 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2017-0246 HIGH 7.0 microsoft windows_10 The Graphics Component in the kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges 1.3%
CVE-2023-33159 HIGH 8.8 microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability 1.3%
CVE-2020-1419 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, CVE-2020-1389, CVE-2020-1426. 1.3%
CVE-2008-6819 MED 4.7 microsoft windows_2003_server win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via vectors related to CreateWindow, TranslateMessage, and DispatchMessage, possibly a race condition between threads, a different vulnerabilit 1.3%
CVE-2023-48693 HIGH 8.7 microsoft azure_rtos_threadx Azure RTOS ThreadX is an advanced real-time operating system (RTOS) designed specifically for deeply embedded applications. An attacker can cause arbitrary read and write due to vulnerability in parameter checking mechanism in Azure RTOS ThreadX, which may le 1.3%
CVE-2021-36931 MED 4.4 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.3%
CVE-2021-1676 MED 5.5 microsoft windows_10 Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability 1.3%
CVE-2020-1075 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. A attacker could e 1.3%
CVE-2020-0894 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- 1.3%
CVE-2020-0893 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- 1.3%
CVE-2020-17147 HIGH 8.7 microsoft dynamics_365 Dynamics CRM Webclient Cross-site Scripting Vulnerability 1.3%
CVE-2025-30384 HIGH 7.4 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. 1.3%
CVE-2023-24023 MED 6.8 bluetooth bluetooth_core_specification Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-in-the-middle attacks that force a short key length, and might lead to discovery of the encryption key and live 1.3%
CVE-2020-0792 HIGH 8.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0715, CVE-2020-0745. 1.3%
CVE-2005-3173 MED 4.6 microsoft windows_2000 Microsoft Windows 2000 before Update Rollup 1 for SP4 does not apply group policies if the user logs on using UPN credentials with a trailing dot, which prevents Windows 2000 from finding the correct domain controller and could allow the user to bypass intende 1.3%
CVE-2020-0622 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. 1.3%
CVE-2021-28452 HIGH 7.1 microsoft 365_apps Microsoft Outlook Memory Corruption Vulnerability 1.3%
CVE-2020-0820 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'. 1.3%
CVE-2002-2202 LOW 3.8 microsoft outlook_express Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted items folder, which allows local users to read other users email. 1.3%
CVE-2025-29967 HIGH 8.8 microsoft windows_10_1507 Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. 1.3%
CVE-2025-29836 MED 6.5 microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.3%
CVE-2021-34516 HIGH 7.8 microsoft windows_10 Win32k Elevation of Privilege Vulnerability 1.3%
CVE-2025-24996 MED 6.5 microsoft windows_10_1507 External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. 1.3%
CVE-2024-38081 HIGH 7.3 microsoft .net .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability 1.3%
CVE-2022-24495 HIGH 7.0 microsoft windows_10 Windows Direct Show Remote Code Execution Vulnerability 1.3%