IT
56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-1261 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1263. 1.2%
CVE-2020-1120 MED 5.5 microsoft windows_10 A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1244. 1.2%
CVE-2020-0814 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins 1.2%
CVE-2020-16854 MED 5.5 microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit this v 1.2%
CVE-2001-1238 HIGH 7.8 microsoft windows_2000 Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be s 1.2%
CVE-2025-21294 HIGH 8.1 microsoft windows_10_1507 Microsoft Digest Authentication Remote Code Execution Vulnerability 1.2%
CVE-2021-34532 MED 5.5 microsoft asp.net_core ASP.NET Core and Visual Studio Information Disclosure Vulnerability 1.2%
CVE-2020-1471 HIGH 7.3 microsoft windows_10 <p>An elevation of privilege vulnerability exists when Microsoft Windows CloudExperienceHost fails to check COM objects. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system.</p> <p>To exploit the vulnera 1.2%
CVE-2017-11824 HIGH 7.0 microsoft windows_10 The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulne 1.2%
CVE-2021-31969 HIGH 7.8 microsoft windows_10 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 1.2%
CVE-2021-1638 HIGH 7.7 microsoft windows_10 Microsoft is aware of the &quot;Impersonation in the Passkey Entry Protocol&quot; vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software 1.2%
CVE-2018-8313 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windo 1.2%
CVE-2018-8282 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows 1.2%
CVE-2018-8202 HIGH 7.8 microsoft .net_framework An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level, aka ".NET Framework Elevation of Privilege Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, 1.2%
CVE-2024-38108 CRIT 9.3 microsoft azure_stack_hub Azure Stack Hub Spoofing Vulnerability 1.2%
CVE-2023-36788 HIGH 7.8 microsoft .net_framework .NET Framework Remote Code Execution Vulnerability 1.2%
CVE-2025-47957 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 1.2%
CVE-2024-49076 HIGH 7.8 microsoft windows_10_1809 Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability 1.2%
CVE-2023-36742 HIGH 7.8 microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability 1.2%
CVE-2023-21685 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.2%
CVE-2023-24890 MED 6.5 microsoft onedrive Microsoft OneDrive for iOS Security Feature Bypass Vulnerability 1.2%
CVE-2023-36022 MED 6.6 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.2%
CVE-2022-23262 MED 6.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.2%
CVE-2024-29987 MED 6.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability 1.2%
CVE-2023-32021 HIGH 7.1 microsoft windows_server_2012 Windows SMB Witness Service Security Feature Bypass Vulnerability 1.2%