56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-44693 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2001-0349 | HIGH 7.2 | microsoft windows_2000 Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program wi | 1.9% | — |
| CVE-2025-21389 | HIGH 7.5 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network. | 1.9% | — |
| CVE-2019-1081 | MED 4.2 | microsoft edge An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the vuln | 1.9% | — |
| CVE-2023-36401 | HIGH 7.2 | microsoft windows_10_1507 Microsoft Remote Registry Service Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2010-3939 | HIGH 7.2 | microsoft windows_2003_server Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via vectors related to | 1.9% | — |
| CVE-2022-41042 | HIGH 7.4 | microsoft visual_studio_code Visual Studio Code Information Disclosure Vulnerability | 1.9% | — |
| CVE-2023-32011 | HIGH 7.5 | microsoft windows_10_1507 Windows iSCSI Discovery Service Denial of Service Vulnerability | 1.9% | — |
| CVE-2023-28217 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 1.9% | — |
| CVE-2019-1197 | MED 4.2 | microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 1.9% | — |
| CVE-2019-1196 | MED 4.2 | microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 1.9% | — |
| CVE-2019-1139 | MED 4.2 | microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 1.9% | — |
| CVE-2005-2935 | MED 4.6 | microsoft antispyware Unquoted Windows search path vulnerability in Microsoft AntiSpyware might allow local users to execute code via a malicious c:\program.exe file, which is run by AntiSpywareMain.exe when it attempts to execute gsasDtServ.exe. NOTE: it is not clear whether this | 1.9% | — |
| CVE-2021-4287 | MED 5.0 | microsoft binwalk A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2. Affected is an unknown function of the file src/binwalk/modules/extractor.py of the component Archive Extraction Handler. The manipulation leads to symlink foll | 1.9% | — |
| CVE-2026-41096 | CRIT 9.8 | microsoft windows_11_23h2 Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. | 1.9% | — |
| CVE-2010-0234 | MED 4.7 | microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate a registry-key argument to an unspecified system call, which allows local users to cause a denial of se | 1.9% | — |
| CVE-2021-31984 | HIGH 7.6 | microsoft power_bi_report_server Power BI Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2026-32184 | HIGH 7.8 | microsoft hpc_pack Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authorized attacker to elevate privileges locally. | 1.9% | — |
| CVE-2022-24472 | HIGH 8.0 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1.9% | — |
| CVE-2020-0624 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0642. | 1.9% | — |
| CVE-2004-0211 | LOW 2.1 | microsoft windows_2003_server The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program. | 1.9% | — |
| CVE-2026-32192 | HIGH 7.8 | microsoft azure_monitor_agent Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | 1.9% | — |
| CVE-2024-20663 | MED 6.5 | microsoft windows_10_1507 Windows Message Queuing Client (MSMQC) Information Disclosure | 1.9% | — |
| CVE-2000-0088 | HIGH 7.2 | microsoft office Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malformed Conversion Data" vulnerability. | 1.9% | — |
| CVE-2011-0039 | HIGH 7.2 | microsoft windows_2003_server The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length | 1.9% | — |