IT
56.704 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-1296 MED 5.5 microsoft windows_10 A vulnerability exists in the way the Windows Diagnostics & feedback settings app handles objects in memory, aka 'Windows Diagnostics & feedback Information Disclosure Vulnerability'. 1.3%
CVE-2026-62878 CRIT 9.8 microsoft windows_10_1607 Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. 1.3%
CVE-2026-42985 HIGH 8.8 microsoft remote_desktop_client Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 1.3%
CVE-2024-43474 HIGH 7.6 microsoft sql_server_2017 Microsoft SQL Server Information Disclosure Vulnerability 1.3%
CVE-2024-30098 HIGH 7.5 microsoft windows_10_1507 Windows Cryptographic Services Security Feature Bypass Vulnerability 1.3%
CVE-2023-41774 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-41773 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2020-17020 LOW 3.3 microsoft 365_apps Microsoft Word Security Feature Bypass Vulnerability 1.3%
CVE-2026-42835 HIGH 8.1 microsoft teams Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. 1.3%
CVE-2020-1331 MED 5.4 microsoft system_center_operations_manager A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System Center Operations Manager Spoofing Vulnerability'. 1.3%
CVE-2023-41771 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-41770 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-41769 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-41768 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-41767 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-41765 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-38166 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-23400 HIGH 7.2 microsoft windows_server_2012 Windows DNS Server Remote Code Execution Vulnerability 1.3%
CVE-2026-70321 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.3%
CVE-2021-43220 LOW 3.1 microsoft edge_ios Microsoft Edge for iOS Spoofing Vulnerability 1.3%
CVE-2021-42308 LOW 3.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 1.3%
CVE-2026-50517 CRIT 9.9 microsoft 365_copilot Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. 1.3%
CVE-2021-1672 MED 5.5 microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability 1.3%
CVE-2019-0965 HIGH 7.6 microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a 1.3%
CVE-2020-16921 MED 5.5 microsoft windows_10 <p>An information disclosure vulnerability exists in Text Services Framework when it fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could potentially read data that was not intended to be disclosed. Note t 1.3%