IT
56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-0976 MED 5.5 microsoft nuget A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify contents of the intermediate build folder (by default "obj"), aka 'NuGet Package Manager Tampering Vulnerability'. 1.2%
CVE-2023-21686 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.1%
CVE-2019-0656 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. 1.1%
CVE-2017-8694 HIGH 7.0 microsoft windows_10 The Microsoft Windows Kernel Mode Driver on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privile 1.1%
CVE-2017-8689 HIGH 7.0 microsoft windows_10 The Microsoft Windows Kernel Mode Driver on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privile 1.1%
CVE-2024-43488 HIGH 8.8 microsoft visual_studio_code Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector. 1.1%
CVE-2023-29337 HIGH 7.1 microsoft nuget NuGet Client Remote Code Execution Vulnerability 1.1%
CVE-2023-21808 HIGH 7.8 microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability 1.1%
CVE-2024-38053 HIGH 8.8 microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability 1.1%
CVE-2021-26866 HIGH 7.1 microsoft windows_10 Windows Update Service Elevation of Privilege Vulnerability 1.1%
CVE-2018-1036 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows S 1.1%
CVE-2025-27744 HIGH 7.8 microsoft office Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally. 1.1%
CVE-2021-36963 HIGH 7.8 microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability 1.1%
CVE-2017-0156 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists in Windows 7, Windows 8.1, Windows RT 8.1, Windows 10, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 when the Microsoft Graphics Component fails to properly handle ob 1.1%
CVE-2025-50156 MED 5.7 microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. 1.1%
CVE-2025-21259 MED 5.3 microsoft outlook Microsoft Outlook Spoofing Vulnerability 1.1%
CVE-2024-21395 HIGH 8.2 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 1.1%
CVE-2025-21210 MED 4.2 microsoft windows_10_1507 Windows BitLocker Information Disclosure Vulnerability 1.1%
CVE-2025-21186 HIGH 7.8 microsoft 365_apps Microsoft Access Remote Code Execution Vulnerability 1.1%
CVE-2021-26873 HIGH 7.0 microsoft windows_10 Windows User Profile Service Elevation of Privilege Vulnerability 1.1%
CVE-2026-56168 MED 6.5 microsoft windows_10_21h2 Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network. 1.1%
CVE-2026-50366 MED 6.5 microsoft windows_10_1607 Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. 1.1%
CVE-2026-57976 MED 6.5 microsoft windows_10_1607 Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. 1.1%
CVE-2026-49799 MED 6.5 microsoft windows_10_1607 Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. 1.1%
CVE-2024-30093 HIGH 7.3 microsoft windows_10_1507 Windows Storage Elevation of Privilege Vulnerability 1.1%