IT
56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-36433 MED 6.5 microsoft dynamics_365 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability 1.9%
CVE-2024-26165 HIGH 8.8 microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability 1.9%
CVE-2017-0096 LOW 2.6 microsoft windows_10 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to obtain sensitive information from host OS mem 1.9%
CVE-2015-2534 LOW 1.9 microsoft windows_10 Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 improperly processes ACL settings, which allows local users to bypass intended network-traffic restrictions via a crafted application, aka "Hyper-V Security Feature Bypass Vulnerability." 1.9%
CVE-2024-20662 MED 4.9 microsoft windows_server_2008 Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability 1.9%
CVE-2018-8434 MED 5.4 microsoft windows_10 An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Information Disclosure Vulnerability." This affects Win 1.9%
CVE-2025-27486 HIGH 7.5 microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. 1.9%
CVE-2025-27485 HIGH 7.5 microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. 1.9%
CVE-2025-21174 HIGH 7.5 microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. 1.9%
CVE-2010-2554 HIGH 7.8 microsoft windows_7 The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on its registry keys, which allows local users to gain privileges via vectors involving a named pipe and impersonat 1.9%
CVE-2021-43876 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Elevation of Privilege Vulnerability 1.9%
CVE-2018-8116 MED 5.5 microsoft windows_10 A denial of service vulnerability exists in the way that Windows handles objects in memory, aka "Microsoft Graphics Component Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 1.9%
CVE-2001-0344 HIGH 7.2 microsoft sql_server An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account. 1.9%
CVE-2021-1705 MED 4.2 microsoft edge Microsoft Edge (HTML-based) Memory Corruption Vulnerability 1.9%
CVE-2020-1200 HIGH 8.6 microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the ShareP 1.9%
CVE-2026-26142 CRIT 9.8 microsoft nuance_powerscribe_360 Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network. 1.9%
CVE-2021-33753 MED 4.7 microsoft bing Microsoft Bing Search Spoofing Vulnerability 1.9%
CVE-2005-4697 LOW 2.1 microsoft windows_xp The Microsoft Wireless Zero Configuration system (WZCS) allows local users to access WEP keys and pair-wise Master Keys (PMK) of the WPA pre-shared key via certain calls to the WZCQueryInterface API function in wzcsapi.dll. 1.9%
CVE-2024-30017 HIGH 8.8 microsoft windows_10_1507 Windows Hyper-V Remote Code Execution Vulnerability 1.9%
CVE-2025-21307 CRIT 9.8 microsoft windows_10_1507 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability 1.9%
CVE-2018-8212 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 1.9%
CVE-2026-64901 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.9%
CVE-2025-21224 HIGH 8.1 microsoft windows_10_21h2 Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability 1.9%
CVE-2023-36763 HIGH 7.5 microsoft 365_apps Microsoft Outlook Information Disclosure Vulnerability 1.9%
CVE-2022-34714 HIGH 8.1 microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 1.9%