IT
56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-28290 MED 5.3 microsoft remote_desktop_app Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability 1.2%
CVE-2022-30175 HIGH 7.8 microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability 1.2%
CVE-2021-26431 HIGH 7.8 microsoft windows_10 Windows Recovery Environment Agent Elevation of Privilege Vulnerability 1.2%
CVE-2020-1398 MED 6.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly handle Ease of Access dialog.An attacker who successfully exploited the vulnerability could execute commands with elevated permissions.The security update addresses the vu 1.2%
CVE-2019-1065 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, 1.2%
CVE-2017-11818 MED 4.5 microsoft windows_10 The Microsoft Windows Storage component on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass vulnerability when it fails to validate an integrity-level 1.2%
CVE-2026-54118 CRIT 9.8 microsoft sql_server_2016 Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. 1.2%
CVE-2026-54117 CRIT 9.8 microsoft sql_server_2016 Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. 1.2%
CVE-2026-35435 HIGH 8.6 microsoft azure_ai_foundry Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. 1.2%
CVE-2024-38089 CRIT 9.1 microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability 1.2%
CVE-2023-28271 MED 5.5 microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability 1.2%
CVE-2022-23269 MED 5.4 microsoft dynamics_gp Microsoft Dynamics GP Spoofing Vulnerability 1.2%
CVE-2020-24003 LOW 3.3 microsoft skype Microsoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Skype Cli 1.2%
CVE-2011-1874 HIGH 7.8 microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain 1.2%
CVE-2023-21539 HIGH 7.5 microsoft windows_10_20h2 Windows Authentication Remote Code Execution Vulnerability 1.2%
CVE-2024-28899 HIGH 8.8 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 1.2%
CVE-2023-36037 HIGH 7.8 microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability 1.2%
CVE-2026-26105 HIGH 8.1 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 1.2%
CVE-2024-38263 HIGH 7.5 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability 1.2%
CVE-2026-20929 HIGH 7.5 microsoft windows_10_1607 Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. 1.2%
CVE-2025-26668 HIGH 7.5 microsoft windows_10_1507 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 1.2%
CVE-2020-1033 MED 4.0 microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>An authenticated 1.2%
CVE-2017-8579 HIGH 7.0 microsoft windows_10 The DirectX component in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to run arbitrary code in kernel mode via a specially crafted application, aka "DirectX Elevation of Privilege Vulnerability." 1.2%
CVE-2024-21396 HIGH 7.6 microsoft dynamics_365 Dynamics 365 Sales Spoofing Vulnerability 1.2%
CVE-2024-21393 HIGH 7.6 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 1.2%