IT
56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2013-3173 HIGH 7.2 microsoft windows_7 Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to ga 2.0%
CVE-2020-1595 CRIT 9.9 microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application 2.0%
CVE-2019-1440 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1436. 2.0%
CVE-2022-38006 MED 6.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 2.0%
CVE-2026-62741 HIGH 7.8 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 2.0%
CVE-2026-61930 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 2.0%
CVE-2023-36437 HIGH 8.8 microsoft azure_pipelines_agent Azure DevOps Server Remote Code Execution Vulnerability 2.0%
CVE-2015-2454 LOW 2.1 microsoft windows_7 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local 2.0%
CVE-2026-62713 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 1.9%
CVE-2021-34517 MED 5.3 microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability 1.9%
CVE-2021-3339 MED 4.3 microsoft modernflow ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen. 1.9%
CVE-2022-37959 MED 6.5 microsoft windows_server_2012 Network Device Enrollment Service (NDES) Security Feature Bypass Vulnerability 1.9%
CVE-2002-0034 MED 4.6 microsoft windows_2000 The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than ex 1.9%
CVE-2025-21217 MED 6.5 microsoft windows_10_1507 Windows NTLM Spoofing Vulnerability 1.9%
CVE-2022-35802 HIGH 8.1 microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability 1.9%
CVE-2024-26161 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.9%
CVE-2024-26159 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.9%
CVE-2024-21451 HIGH 8.8 microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.9%
CVE-2024-21444 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.9%
CVE-2024-21441 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.9%
CVE-2022-33655 MED 6.5 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 1.9%
CVE-2017-8494 HIGH 7.3 microsoft windows_10 Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a locally-authenticated attacker to run a specially crafted application on a targeted system when Windows Secure Kernel Mode fails to properly handle objects in memory, aka "Windows 1.9%
CVE-2020-1044 MED 4.3 microsoft sql_server_reporting_services <p>A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to reports. An attacker who successfully exploited this vulnerability could upload file types that were disallow 1.9%
CVE-2019-1198 MED 6.5 microsoft windows_10 An elevation of privilege exists in SyncController.dll. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could e 1.9%
CVE-2023-32014 CRIT 9.8 microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability 1.9%