56.672 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-0246 | HIGH 7.0 | microsoft windows_10 The Graphics Component in the kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges | 1.3% | — |
| CVE-2023-33159 | HIGH 8.8 | microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability | 1.3% | — |
| CVE-2020-1419 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, CVE-2020-1389, CVE-2020-1426. | 1.3% | — |
| CVE-2008-6819 | MED 4.7 | microsoft windows_2003_server win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via vectors related to CreateWindow, TranslateMessage, and DispatchMessage, possibly a race condition between threads, a different vulnerabilit | 1.3% | — |
| CVE-2023-48693 | HIGH 8.7 | microsoft azure_rtos_threadx Azure RTOS ThreadX is an advanced real-time operating system (RTOS) designed specifically for deeply embedded applications. An attacker can cause arbitrary read and write due to vulnerability in parameter checking mechanism in Azure RTOS ThreadX, which may le | 1.3% | — |
| CVE-2021-36931 | MED 4.4 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2021-1676 | MED 5.5 | microsoft windows_10 Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability | 1.3% | — |
| CVE-2020-1075 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. A attacker could e | 1.3% | — |
| CVE-2020-0894 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- | 1.3% | — |
| CVE-2020-0893 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- | 1.3% | — |
| CVE-2020-17147 | HIGH 8.7 | microsoft dynamics_365 Dynamics CRM Webclient Cross-site Scripting Vulnerability | 1.3% | — |
| CVE-2025-30384 | HIGH 7.4 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | 1.3% | — |
| CVE-2023-24023 | MED 6.8 | bluetooth bluetooth_core_specification Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-in-the-middle attacks that force a short key length, and might lead to discovery of the encryption key and live | 1.3% | — |
| CVE-2020-0792 | HIGH 8.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0715, CVE-2020-0745. | 1.3% | — |
| CVE-2005-3173 | MED 4.6 | microsoft windows_2000 Microsoft Windows 2000 before Update Rollup 1 for SP4 does not apply group policies if the user logs on using UPN credentials with a trailing dot, which prevents Windows 2000 from finding the correct domain controller and could allow the user to bypass intende | 1.3% | — |
| CVE-2020-0622 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. | 1.3% | — |
| CVE-2021-28452 | HIGH 7.1 | microsoft 365_apps Microsoft Outlook Memory Corruption Vulnerability | 1.3% | — |
| CVE-2020-0820 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'. | 1.3% | — |
| CVE-2002-2202 | LOW 3.8 | microsoft outlook_express Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted items folder, which allows local users to read other users email. | 1.3% | — |
| CVE-2025-29967 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2025-29836 | MED 6.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.3% | — |
| CVE-2021-34516 | HIGH 7.8 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2025-24996 | MED 6.5 | microsoft windows_10_1507 External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | 1.3% | — |
| CVE-2024-38081 | HIGH 7.3 | microsoft .net .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2022-24495 | HIGH 7.0 | microsoft windows_10 Windows Direct Show Remote Code Execution Vulnerability | 1.3% | — |