56.696 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-33768 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2025-49760 | LOW 3.5 | microsoft windows_10_1507 External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network. | 1.3% | — |
| CVE-2025-32715 | MED 6.5 | microsoft remote_desktop_client Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | 1.3% | — |
| CVE-2006-0023 | MED 4.3 | microsoft windows_xp Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Se | 1.3% | — |
| CVE-2025-59228 | HIGH 8.8 | microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.3% | — |
| CVE-2023-35642 | MED 6.5 | microsoft windows_10_1507 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 1.3% | — |
| CVE-2022-22002 | MED 5.5 | microsoft windows_10 Windows User Account Profile Picture Denial of Service Vulnerability | 1.3% | — |
| CVE-2026-55944 | CRIT 9.8 | microsoft dynamics_nav Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2021-28321 | HIGH 7.8 | microsoft visual_studio Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2024-38194 | HIGH 8.4 | microsoft azure_web_apps An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network. | 1.3% | — |
| CVE-2024-38099 | MED 5.9 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Denial of Service Vulnerability | 1.3% | — |
| CVE-2023-41766 | HIGH 7.8 | microsoft windows_10_1507 Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2025-21222 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2025-21221 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2025-21205 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2021-27080 | CRIT 9.3 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1.3% | — |
| CVE-2016-7222 | HIGH 7.8 | microsoft windows_10 Task Scheduler in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows local users to gain privileges via a crafted UNC pathname in a task, aka "Task Scheduler Elevation of Privilege Vulnerability." | 1.3% | — |
| CVE-2023-36016 | MED 6.2 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 1.3% | — |
| CVE-2021-42323 | LOW 3.3 | microsoft azure_real_time_operating_system Azure RTOS Information Disclosure Vulnerability | 1.3% | — |
| CVE-2020-0918 | MED 6.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0917. | 1.3% | — |
| CVE-2020-0669 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0668, CVE-2020-0670, CVE-2020-0671, CVE-2020-0672. | 1.3% | — |
| CVE-2025-30391 | HIGH 8.1 | microsoft dynamics_365_customer_service Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network. | 1.3% | — |
| CVE-2021-36962 | MED 5.5 | microsoft windows_10 Windows Installer Information Disclosure Vulnerability | 1.3% | — |
| CVE-2020-16987 | HIGH 7.3 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1.3% | — |
| CVE-2024-49127 | HIGH 8.1 | microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1.3% | — |