IT
56.721 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.472 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-30072 HIGH 7.8 microsoft windows_11_22h2 Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability 0.9%
CVE-2023-35629 MED 6.8 microsoft windows_10_1507 Microsoft USBHUB 3.0 Device Driver Remote Code Execution Vulnerability 0.9%
CVE-2025-24055 MED 4.3 microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack. 0.9%
CVE-2024-26193 MED 6.4 microsoft azure_migrate Azure Migrate Remote Code Execution Vulnerability 0.9%
CVE-2020-1251 MED 6.7 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1253, 0.9%
CVE-2026-70328 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-70327 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2023-28308 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0.9%
CVE-2023-28307 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0.9%
CVE-2023-28306 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0.9%
CVE-2023-28305 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0.9%
CVE-2023-28278 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0.9%
CVE-2020-1402 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows ActiveX Installer Service Eleva 0.9%
CVE-2020-0799 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows when the Windows kernel fails to properly handle parsing of certain symbolic links, aka 'Windows Kernel Elevation of Privilege Vulnerability'. 0.9%
CVE-2026-45584 HIGH 8.1 microsoft malware_protection_engine Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2025-49670 MED 6.5 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2023-36030 MED 6.1 microsoft dynamics_365 Microsoft Dynamics 365 Sales Spoofing Vulnerability 0.9%
CVE-2021-26428 MED 4.4 microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability 0.9%
CVE-2021-34462 HIGH 7.0 microsoft windows_10 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability 0.9%
CVE-2021-1695 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.9%
CVE-2023-36728 MED 5.5 microsoft odbc_driver_for_sql_server Microsoft SQL Server Denial of Service Vulnerability 0.9%
CVE-2020-16998 HIGH 7.0 microsoft windows_10 DirectX Elevation of Privilege Vulnerability 0.9%
CVE-2025-25006 MED 5.3 microsoft exchange_server Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 0.9%
CVE-2025-21323 MED 5.5 microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability 0.9%
CVE-2025-21317 MED 5.5 microsoft windows_10_21h2 Windows Kernel Memory Information Disclosure Vulnerability 0.9%