IT
56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-24908 HIGH 8.1 microsoft windows_10_1507 Remote Procedure Call Runtime Remote Code Execution Vulnerability 1.0%
CVE-2023-24869 HIGH 8.1 microsoft windows_10_1507 Remote Procedure Call Runtime Remote Code Execution Vulnerability 1.0%
CVE-2023-23405 HIGH 8.1 microsoft windows_10_1507 Remote Procedure Call Runtime Remote Code Execution Vulnerability 1.0%
CVE-2021-40488 HIGH 7.8 microsoft windows_10 Storage Spaces Controller Elevation of Privilege Vulnerability 1.0%
CVE-2020-0810 HIGH 7.8 microsoft visual_studio_2015 An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system.An 1.0%
CVE-2019-1317 HIGH 7.3 microsoft windows_10 A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'. 1.0%
CVE-2019-1256 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1285. 1.0%
CVE-2017-8566 HIGH 7.0 microsoft windows_10 Microsoft Windows 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Windows Input Method Editor (IME) improperly handling parameters in a method of a DCOM class, aka "Windows IME Elevation of Privilege Vulnerability". 1.0%
CVE-2024-38032 HIGH 7.1 microsoft windows_10_21h2 Microsoft Xbox Remote Code Execution Vulnerability 1.0%
CVE-2023-36765 HIGH 7.8 microsoft office Microsoft Office Elevation of Privilege Vulnerability 1.0%
CVE-2026-21265 MED 6.4 microsoft windows_10_1607 Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising 1.0%
CVE-2020-16913 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could th 1.0%
CVE-2020-16907 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could th 1.0%
CVE-2020-16890 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; vi 1.0%
CVE-2020-0703 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Service Elevation of Privi 1.0%
CVE-2023-36803 MED 5.5 microsoft windows_10_1607 Windows Kernel Information Disclosure Vulnerability 1.0%
CVE-2023-33135 HIGH 7.3 microsoft .net .NET and Visual Studio Elevation of Privilege Vulnerability 1.0%
CVE-2023-33128 HIGH 7.3 microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability 1.0%
CVE-2023-33126 HIGH 7.3 microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability 1.0%
CVE-2017-8580 HIGH 7.0 microsoft windows_10 Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to 1.0%
CVE-2024-43610 HIGH 7.4 microsoft copilot_studio Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector 1.0%
CVE-2024-38211 HIGH 8.2 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 1.0%
CVE-2022-34723 MED 5.5 microsoft windows_11 Windows DPAPI (Data Protection Application Programming Interface) Information Disclosure Vulnerability 1.0%
CVE-2022-30176 HIGH 7.8 microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability 1.0%
CVE-2020-17001 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 1.0%