IT
56.696 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-49126 HIGH 8.1 microsoft windows_10_1507 Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability 1.3%
CVE-2024-20689 HIGH 7.1 microsoft windows_server_2012 Secure Boot Security Feature Bypass Vulnerability 1.3%
CVE-2024-20688 HIGH 7.1 microsoft windows_server_2012 Secure Boot Security Feature Bypass Vulnerability 1.3%
CVE-2020-0981 HIGH 8.8 microsoft windows_10 A security feature bypass vulnerability exists when Windows fails to properly handle token relationships.An attacker who successfully exploited the vulnerability could allow an application with a certain integrity level to execute code at a different integrity 1.3%
CVE-2020-16986 MED 6.2 microsoft azure_sphere Azure Sphere Denial of Service Vulnerability 1.3%
CVE-2024-30082 HIGH 7.8 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 1.3%
CVE-2025-29835 MED 6.5 microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.3%
CVE-2025-29832 MED 6.5 microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.3%
CVE-2025-29830 MED 6.5 microsoft windows_10_1507 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.3%
CVE-2025-21286 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.3%
CVE-2025-21282 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.3%
CVE-2025-21273 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.3%
CVE-2025-21266 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.3%
CVE-2024-21390 HIGH 7.1 microsoft authenticator Microsoft Authenticator Elevation of Privilege Vulnerability 1.3%
CVE-2023-33144 MED 6.6 microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability 1.3%
CVE-2018-0963 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. 1.3%
CVE-2024-38129 HIGH 7.5 microsoft windows_server_2022_23h2 Windows Kerberos Elevation of Privilege Vulnerability 1.3%
CVE-2019-1053 MED 6.3 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would 1.3%
CVE-2024-38011 HIGH 8.0 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 1.3%
CVE-2024-37987 HIGH 8.0 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 1.3%
CVE-2024-37975 HIGH 8.0 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 1.3%
CVE-2012-0180 HIGH 7.8 microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input pass 1.3%
CVE-2017-8468 HIGH 7.8 microsoft windows_10 Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to run processes in an elevated context when the Windows kernel improperly handles objects in memory, aka "Win32k 1.3%
CVE-2009-2508 MED 6.9 microsoft windows_server_2003 The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers 1.3%
CVE-2020-1361 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists in the way that the WalletService handles memory.To exploit the vulnerability, an attacker would first need code execution on a victim system, aka 'Windows WalletService Information Disclosure Vulnerability'. 1.3%