IT
56.672 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2018-8166 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 20 1.3%
CVE-2007-3724 LOW 2.1 microsoft windows_xp The process scheduler in the Microsoft Windows XP kernel does not make use of the process statistics kept by the kernel, performs scheduling based on CPU billing gathered from periodic process sampling ticks, and gives preference to "interactive" processes tha 1.3%
CVE-2026-20803 HIGH 7.2 microsoft sql_server_2022 Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network. 1.3%
CVE-2022-37956 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 1.3%
CVE-2025-50166 MED 6.5 microsoft windows_10_1507 Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose information over a network. 1.3%
CVE-2024-21327 HIGH 7.6 microsoft dynamics_365 Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability 1.3%
CVE-2023-38155 HIGH 7.0 microsoft azure_devops_server Azure DevOps Server Remote Code Execution Vulnerability 1.3%
CVE-2023-24913 HIGH 8.8 microsoft windows_10_1607 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability 1.3%
CVE-2023-24909 HIGH 8.8 microsoft windows_10_1607 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability 1.3%
CVE-2023-24907 HIGH 8.8 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability 1.3%
CVE-2023-24872 HIGH 8.8 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability 1.3%
CVE-2023-24868 HIGH 8.8 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability 1.3%
CVE-2023-24867 HIGH 8.8 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability 1.3%
CVE-2023-24864 HIGH 8.8 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Elevation of Privilege Vulnerability 1.3%
CVE-2023-23413 HIGH 8.8 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability 1.3%
CVE-2023-23406 HIGH 8.8 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability 1.3%
CVE-2023-23403 HIGH 8.8 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability 1.3%
CVE-2023-21684 HIGH 8.8 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability 1.3%
CVE-2026-54118 CRIT 9.8 microsoft sql_server_2016 Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. 1.3%
CVE-2026-54117 CRIT 9.8 microsoft sql_server_2016 Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. 1.3%
CVE-2025-62549 HIGH 8.8 microsoft windows_10_1607 Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 1.3%
CVE-2022-21876 MED 5.5 microsoft windows_10 Win32k Information Disclosure Vulnerability 1.3%
CVE-2021-31948 HIGH 7.6 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 1.3%
CVE-2024-21443 HIGH 7.3 microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability 1.3%
CVE-2023-1017 HIGH 7.8 microsoft windows_10_1507 An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of s 1.3%