56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2002-2028 | LOW 2.1 | microsoft windows_2000 The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has already been locked when a valid password is provided, which makes it easier for users with physical access to conduct brute force password guessing. | 2.0% | — |
| CVE-2023-38172 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 2.0% | — |
| CVE-2021-42275 | HIGH 8.8 | microsoft windows_10 Microsoft COM for Windows Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2019-0986 | MED 6.3 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To exploit this vulnera | 2.0% | — |
| CVE-2015-2465 | LOW 2.1 | microsoft windows_10 The Windows shell in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 does not properly constrain impersonation levels, which allows | 2.0% | — |
| CVE-2026-33110 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2.0% | — |
| CVE-2022-41058 | HIGH 7.5 | microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.0% | — |
| CVE-2022-41053 | HIGH 7.5 | microsoft windows_10 Windows Kerberos Denial of Service Vulnerability | 2.0% | — |
| CVE-2024-30090 | HIGH 7.0 | microsoft windows_10_1507 Microsoft Streaming Service Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2022-30211 | HIGH 7.5 | microsoft windows_10 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2021-33754 | HIGH 8.0 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2024-26244 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2024-26210 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2014-1814 | HIGH 7.2 | microsoft windows_7 The Windows Installer in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a c | 2.0% | — |
| CVE-2000-0663 | MED 4.6 | microsoft windows_2000 The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, | 2.0% | — |
| CVE-2025-47165 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 2.0% | — |
| CVE-2025-21330 | HIGH 7.5 | microsoft windows_10_1809 Windows Remote Desktop Services Denial of Service Vulnerability | 2.0% | — |
| CVE-2023-35338 | HIGH 7.5 | microsoft windows_10_1507 Windows Peer Name Resolution Protocol Denial of Service Vulnerability | 2.0% | — |
| CVE-2021-24109 | MED 6.8 | microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | 2.0% | — |
| CVE-2010-1887 | MED 4.4 | microsoft windows_2003_server The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate an unspecified system-call argument, which allo | 2.0% | — |
| CVE-2023-29363 | CRIT 9.8 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2018-8140 | MED 6.8 | microsoft windows_10 An Elevation of Privilege vulnerability exists when Cortana retrieves data from user input services without consideration for status, aka "Cortana Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10. | 2.0% | — |
| CVE-2016-0020 | HIGH 7.8 | microsoft windows_7 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "MAPI DLL Loading Elevation of Privilege Vulnerability." | 2.0% | — |
| CVE-2013-6999 | MED 4.0 | microsoft windows_server_2008 The IsHandleEntrySecure function in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 SP2 does not properly validate the tagPROCESSINFO pW32Job field, which allows local users to cause a denial of service (NULL pointer dereference and syst | 2.0% | — |
| CVE-2021-28458 | HIGH 7.8 | microsoft ms-rest-nodeauth Azure ms-rest-nodeauth Library Elevation of Privilege Vulnerability | 2.0% | — |