IT
56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-21325 HIGH 7.8 microsoft printer_metadata_troubleshooter_tool Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability 1.2%
CVE-2022-41061 HIGH 7.8 microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability 1.2%
CVE-2020-17102 MED 5.5 microsoft webp_image_extension WebP Image Extensions Information Disclosure Vulnerability 1.2%
CVE-2011-0676 HIGH 7.8 microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted applica 1.2%
CVE-2026-49181 HIGH 7.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network. 1.2%
CVE-2024-21376 CRIT 9.0 microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability 1.2%
CVE-2026-26125 HIGH 8.6 microsoft payment_orchestrator_service Payment Orchestrator Service Elevation of Privilege Vulnerability 1.2%
CVE-2025-26646 HIGH 8.0 microsoft .net External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. 1.2%
CVE-2025-21417 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.2%
CVE-2024-38184 HIGH 7.8 microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 1.2%
CVE-2018-0983 HIGH 7.0 microsoft windows_10 Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Storage Services Elevation 1.2%
CVE-2024-0056 HIGH 8.7 microsoft .net Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability 1.2%
CVE-2018-0756 HIGH 7.8 microsoft windows_10 The Windows kernel in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Kernel Elevation of Privilege Vulne 1.2%
CVE-2017-11782 HIGH 7.8 microsoft windows_10 The Microsoft Server Block Message (SMB) on Microsoft Windows 10 1607 and Windows Server 2016, allows an elevation of privilege vulnerability when an attacker sends specially crafted requests to the server, aka "Windows SMB Elevation of Privilege Vulnerability 1.2%
CVE-2017-8503 HIGH 8.8 microsoft edge Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to escape from the AppContainer sandbox, aka "Microsoft Edge Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8642. 1.2%
CVE-2011-1236 HIGH 7.8 microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain 1.2%
CVE-2023-36871 MED 6.5 microsoft windows_10_1507 Azure Active Directory Security Feature Bypass Vulnerability 1.2%
CVE-2011-1887 HIGH 7.8 microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a 1.2%
CVE-2025-27481 HIGH 8.8 microsoft windows_10_1507 Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. 1.2%
CVE-2025-27471 MED 5.9 microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network. 1.2%
CVE-2023-29352 MED 6.5 microsoft remote_desktop_client Windows Remote Desktop Security Feature Bypass Vulnerability 1.2%
CVE-1999-0824 MED 4.6 microsoft windows_nt A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users. 1.2%
CVE-1999-0384 MED 4.6 microsoft office The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content. 1.2%
CVE-2025-24994 HIGH 7.3 microsoft windows_11_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. 1.2%
CVE-2013-1283 MED 6.9 microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows loca 1.2%