56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-8712 | MED 5.3 | microsoft windows_10 The Windows Hyper-V component on Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information D | 2.1% | — |
| CVE-2017-8711 | MED 5.3 | microsoft windows_10 The Windows Hyper-V component on Microsoft Windows 10 1607 and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosu | 2.1% | — |
| CVE-2001-0666 | LOW 2.1 | microsoft exchange_server Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox. | 2.1% | — |
| CVE-2017-0189 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows 10 when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode, aka "Win32k Elevatio | 2.1% | — |
| CVE-2026-26127 | HIGH 7.5 | microsoft .net Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network. | 2.0% | — |
| CVE-2020-17015 | MED 4.3 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 2.0% | — |
| CVE-2001-1497 | LOW 2.1 | microsoft ie Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier t | 2.0% | — |
| CVE-2022-26917 | HIGH 7.8 | microsoft windows_10 Windows Fax Compose Form Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-34447 | MED 6.8 | microsoft windows_10 Windows MSHTML Platform Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-34446 | HIGH 8.0 | microsoft windows_10 Windows HTML Platforms Security Feature Bypass Vulnerability | 2.0% | — |
| CVE-2019-0557 | MED 5.4 | microsoft sharepoint_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoi | 2.0% | — |
| CVE-2026-21262 | HIGH 8.8 | microsoft sql_server_2016 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | 2.0% | — |
| CVE-2025-47978 | MED 6.5 | microsoft windows_server_2022 Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. | 2.0% | — |
| CVE-2022-37955 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2021-28447 | MED 4.4 | microsoft windows_10 Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability | 2.0% | — |
| CVE-2024-49089 | HIGH 7.2 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2018-8164 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 20 | 2.0% | — |
| CVE-2015-6113 | LOW 2.1 | microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass intended filesystem permis | 2.0% | — |
| CVE-2024-20680 | MED 6.5 | microsoft windows_10_1507 Windows Message Queuing Client (MSMQC) Information Disclosure | 2.0% | — |
| CVE-2024-20660 | MED 6.5 | microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability | 2.0% | — |
| CVE-2023-36596 | HIGH 7.5 | microsoft windows_10_1507 Remote Procedure Call Information Disclosure Vulnerability | 2.0% | — |
| CVE-2023-32015 | CRIT 9.8 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2023-36429 | MED 6.5 | microsoft dynamics_365 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | 2.0% | — |
| CVE-2018-0830 | MED 4.7 | microsoft windows_10 The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulne | 2.0% | — |
| CVE-2018-0829 | MED 4.7 | microsoft windows_10 The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulne | 2.0% | — |