56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1389 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, CVE-2020-1419, CVE-2020-1426. | 1.2% | — |
| CVE-2020-1386 | MED 5.5 | microsoft windows_10 An information vulnerability exists when Windows Connected User Experiences and Telemetry Service improperly discloses file information, aka 'Connected User Experiences and Telemetry Service Information Disclosure Vulnerability'. | 1.2% | — |
| CVE-2020-1367 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1389, CVE-2020-1419, CVE-2020-1426. | 1.2% | — |
| CVE-2020-1330 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability'. | 1.2% | — |
| CVE-2020-1290 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. | 1.2% | — |
| CVE-2012-1868 | MED 6.9 | microsoft windows_xp Race condition in the thread-creation implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3 allows local users to gain privileges via a crafted application, aka "Win32k.sys Race Condition Vulnerability." | 1.2% | — |
| CVE-2012-1867 | HIGH 8.4 | microsoft windows_2003_server Integer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted T | 1.2% | — |
| CVE-2005-3174 | MED 4.6 | microsoft windows_2000 Microsoft Windows 2000 before Update Rollup 1 for SP4 allows users to log on to the domain, even when their password has expired, if the fully qualified domain name (FQDN) is 8 characters long. | 1.2% | — |
| CVE-2005-3171 | MED 4.6 | microsoft windows_2000 Microsoft Windows 2000 before Update Rollup 1 for SP4 records Event ID 1704 to indicate that Group Policy security settings were successfully updated, even when the processing fails such as when Ntuser.pol cannot be accessed, which could cause system administr | 1.2% | — |
| CVE-2023-35350 | HIGH 7.2 | microsoft windows_server_2008 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2019-1303 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerab | 1.2% | — |
| CVE-2018-8119 | MED 5.6 | microsoft c_software_development_kit A spoofing vulnerability exists when the Azure IoT Device Provisioning AMQP Transport library improperly validates certificates over the AMQP protocol, aka "Azure IoT SDK Spoofing Vulnerability." This affects C# SDK, C SDK, Java SDK. | 1.2% | — |
| CVE-2020-1038 | MED 5.5 | microsoft windows_10 <p>A denial of service vulnerability exists when Windows Routing Utilities improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding.</p> <p>To exploit this vulnerability, an a | 1.2% | — |
| CVE-2025-26671 | HIGH 8.1 | microsoft windows_server_2008 Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1.2% | — |
| CVE-2023-21720 | MED 5.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Tampering Vulnerability | 1.2% | — |
| CVE-2023-35333 | HIGH 8.8 | microsoft pandocupload MediaWiki PandocUpload Extension Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2025-53719 | MED 5.7 | microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | 1.2% | — |
| CVE-2018-0846 | HIGH 7.8 | microsoft windows_10 The Windows Common Log File System (CLFS) driver in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a | 1.2% | — |
| CVE-2018-0844 | HIGH 7.8 | microsoft windows_10 The Windows Common Log File System (CLFS) driver in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a | 1.2% | — |
| CVE-2026-26144 | HIGH 7.5 | microsoft 365_apps Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 1.2% | — |
| CVE-2025-55225 | MED 6.5 | microsoft windows_server_2008 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.2% | — |
| CVE-2022-34702 | HIGH 8.1 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2025-21253 | MED 5.3 | microsoft edge Microsoft Edge for IOS and Android Spoofing Vulnerability | 1.2% | — |
| CVE-2020-1268 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when a Windows service improperly handles objects in memory, aka 'Windows Service Information Disclosure Vulnerability'. | 1.2% | — |
| CVE-2020-1263 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1261. | 1.2% | — |