56.704 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1296 | MED 5.5 | microsoft windows_10 A vulnerability exists in the way the Windows Diagnostics & feedback settings app handles objects in memory, aka 'Windows Diagnostics & feedback Information Disclosure Vulnerability'. | 1.3% | — |
| CVE-2026-62878 | CRIT 9.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2026-42985 | HIGH 8.8 | microsoft remote_desktop_client Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2024-43474 | HIGH 7.6 | microsoft sql_server_2017 Microsoft SQL Server Information Disclosure Vulnerability | 1.3% | — |
| CVE-2024-30098 | HIGH 7.5 | microsoft windows_10_1507 Windows Cryptographic Services Security Feature Bypass Vulnerability | 1.3% | — |
| CVE-2023-41774 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-41773 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2020-17020 | LOW 3.3 | microsoft 365_apps Microsoft Word Security Feature Bypass Vulnerability | 1.3% | — |
| CVE-2026-42835 | HIGH 8.1 | microsoft teams Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. | 1.3% | — |
| CVE-2020-1331 | MED 5.4 | microsoft system_center_operations_manager A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System Center Operations Manager Spoofing Vulnerability'. | 1.3% | — |
| CVE-2023-41771 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-41770 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-41769 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-41768 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-41767 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-41765 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-38166 | HIGH 8.1 | microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2023-23400 | HIGH 7.2 | microsoft windows_server_2012 Windows DNS Server Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2026-70321 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.3% | — |
| CVE-2021-43220 | LOW 3.1 | microsoft edge_ios Microsoft Edge for iOS Spoofing Vulnerability | 1.3% | — |
| CVE-2021-42308 | LOW 3.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1.3% | — |
| CVE-2026-50517 | CRIT 9.9 | microsoft 365_copilot Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. | 1.3% | — |
| CVE-2021-1672 | MED 5.5 | microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability | 1.3% | — |
| CVE-2019-0965 | HIGH 7.6 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a | 1.3% | — |
| CVE-2020-16921 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists in Text Services Framework when it fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could potentially read data that was not intended to be disclosed. Note t | 1.3% | — |