IT
56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-1670 MED 5.5 microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability 1.2%
CVE-2021-1663 MED 5.5 microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability 1.2%
CVE-2021-1637 MED 5.5 microsoft windows_10 Windows DNS Query Information Disclosure Vulnerability 1.2%
CVE-2026-20921 HIGH 7.5 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. 1.2%
CVE-2002-0725 MED 5.5 microsoft windows_2000 NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit trail instead of the target file. 1.2%
CVE-2021-26892 MED 6.2 microsoft windows_10 Windows Extensible Firmware Interface Security Feature Bypass Vulnerability 1.2%
CVE-2018-0868 HIGH 7.0 microsoft windows_10 Windows Installer in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privi 1.2%
CVE-2021-28483 CRIT 9.0 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 1.2%
CVE-2020-17134 HIGH 7.8 microsoft windows_10 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 1.2%
CVE-2025-49666 HIGH 7.2 microsoft windows_server_2016 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network. 1.2%
CVE-2026-42898 CRIT 9.9 microsoft dynamics_365 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. 1.2%
CVE-2025-32714 HIGH 7.8 microsoft windows_10_1507 Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally. 1.2%
CVE-2024-43613 HIGH 7.2 microsoft azure_database_for_postgresql_flexible_server Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability 1.2%
CVE-2022-21931 MED 4.2 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.2%
CVE-2022-21930 MED 4.2 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.2%
CVE-2018-8561 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 1.2%
CVE-2018-8485 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 1.2%
CVE-2018-8471 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Microsoft RemoteFX Virtual GPU miniport driver handles objects in memory, aka "Microsoft RemoteFX Virtual GPU miniport driver Elevation of Privilege Vulnerability." This affects Windows Server 1.2%
CVE-2018-8343 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it, aka "Windows NDIS Elevation of Privilege Vulnerability." This affects Windows 1.2%
CVE-2018-8342 HIGH 7.8 microsoft windows_7 An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it, aka "Windows NDIS Elevation of Privilege Vulnerability." This affects Windows 1.2%
CVE-2024-49108 HIGH 8.1 microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.2%
CVE-2024-49106 HIGH 8.1 microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.2%
CVE-2024-49042 HIGH 7.2 microsoft azure_database_for_postgresql_flexible_server Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability 1.2%
CVE-2018-8554 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019. This CVE ID is unique from CVE-2018-8485, CV 1.2%
CVE-2018-8462 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 1.2%