56.560 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.453 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2026-55040 | CRIT 9.1 | microsoft sharepoint_server Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. | 1.6% | |
| CVE-2026-33824 | CRIT 9.8 | microsoft windows_10_1607 Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. | 55.9% | |
| CVE-2026-68820 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.4% | |
| CVE-2026-50522 | CRIT 9.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | 77.0% | |
| CVE-2026-58644 | CRIT 9.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | 6.4% | |
| CVE-2026-56164 | MED 5.3 | microsoft sharepoint_server Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. | 22.4% | |
| CVE-2026-56155 | HIGH 7.8 | microsoft windows_10_1607 Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. | 2.3% | |
| CVE-2026-45659 | HIGH 8.8 | ransomware microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 9.1% | |
| CVE-2026-45498 | MED 4.0 | microsoft defender_antimalware_platform Microsoft Defender Denial of Service Vulnerability | 63.1% | |
| CVE-2026-41091 | HIGH 7.8 | microsoft malware_protection_engine Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. | 9.6% | |
| CVE-2010-0806 | HIGH 8.8 | microsoft internet_explorer Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as | 82.2% | |
| CVE-2010-0249 | HIGH 8.8 | microsoft internet_explorer Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers | 91.9% | |
| CVE-2009-1537 | HIGH 8.8 | microsoft directx Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a cr | 51.2% | |
| CVE-2008-4250 | CRIT 9.8 | microsoft windows_2000 The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canoni | 98.8% | |
| CVE-2026-42897 | HIGH 8.1 | microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 70.3% | |
| CVE-2026-32202 | MED 4.3 | microsoft windows_10_1607 Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. | 63.7% | |
| CVE-2026-33825 | HIGH 7.8 | ransomware microsoft defender_antimalware_platform Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. | 6.7% | |
| CVE-2026-32201 | MED 6.5 | microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 22.8% | |
| CVE-2009-0238 | HIGH 8.8 | microsoft excel Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attacker | 43.1% | |
| CVE-2025-60710 | HIGH 7.8 | ransomware microsoft windows_11_24h2 Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. | 4.6% | |
| CVE-2023-36424 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 12.2% | |
| CVE-2023-21529 | HIGH 8.8 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 62.1% | |
| CVE-2012-1854 | HIGH 7.8 | microsoft office Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges v | 21.0% | |
| CVE-2026-20963 | CRIT 9.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | 31.6% | |
| CVE-2008-0015 | HIGH 8.8 | microsoft windows_2003_server Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista G | 76.7% |