IT
56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-27921 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. 1.2%
CVE-2026-26116 HIGH 8.8 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 1.2%
CVE-2026-23674 HIGH 7.5 microsoft windows_10_1607 Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. 1.2%
CVE-2020-1592 MED 4.4 microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.</p> <p>To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploite 1.2%
CVE-2013-1342 HIGH 7.8 microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a 1.2%
CVE-2025-30387 CRIT 9.8 microsoft azure_ai_document_intelligence_studio Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a network. 1.2%
CVE-2023-41764 MED 5.5 microsoft 365_apps Microsoft Office Spoofing Vulnerability 1.2%
CVE-2023-29345 MED 6.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability 1.2%
CVE-2023-21799 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.2%
CVE-2023-21798 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.2%
CVE-2023-21797 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.2%
CVE-2013-1279 HIGH 7.2 microsoft windows_7 Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges 1.2%
CVE-2026-35424 HIGH 7.5 microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2024-20673 HIGH 7.8 microsoft excel Microsoft Office Remote Code Execution Vulnerability 1.2%
CVE-2023-35619 MED 5.3 microsoft office_long_term_servicing_channel Microsoft Outlook for Mac Spoofing Vulnerability 1.2%
CVE-2022-34709 MED 6.0 microsoft windows_10 Windows Defender Credential Guard Security Feature Bypass Vulnerability 1.2%
CVE-2018-8415 HIGH 7.8 microsoft powershell_core A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka "Microsoft PowerShell Tampering Vulnerability." This affects Windows 7, PowerShell Core 6.1, Windows Server 2012 R2, Windows RT 8.1, PowerShell Core 6.0, 1.2%
CVE-2026-57092 CRIT 9.9 microsoft windows_10_1607 Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. 1.2%
CVE-2023-24897 HIGH 7.8 microsoft .net .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability 1.2%
CVE-2018-8549 MED 5.5 microsoft windows_10 A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 201 1.2%
CVE-2025-24061 HIGH 7.8 microsoft windows_10_1507 Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally. 1.2%
CVE-2024-20692 MED 5.7 microsoft windows_10_1507 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability 1.2%
CVE-2020-1548 HIGH 7.8 microsoft windows_10 An information disclosure vulnerability exists when the Windows WaasMedic Service improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted appl 1.2%
CVE-2019-1267 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Compatibility Appraiser where a configuration file, with local privileges, is vulnerable to symbolic link and hard link attacks, aka 'Microsoft Compatibility Appraiser Elevation of Privilege Vulnerabi 1.2%
CVE-2024-30100 HIGH 7.8 microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability 1.2%