IT
56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-24534 HIGH 7.5 microsoft windows_10 Win32 Stream Enumeration Remote Code Execution Vulnerability 1.8%
CVE-2024-38109 CRIT 9.1 microsoft azure_health_bot An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network. 1.8%
CVE-2023-36706 MED 6.5 microsoft windows_server_2008 Windows Deployment Services Information Disclosure Vulnerability 1.8%
CVE-2022-26905 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 1.8%
CVE-2024-43481 MED 6.5 microsoft power_bi_report_server Power BI Report Server Spoofing Vulnerability 1.8%
CVE-2011-0088 HIGH 7.2 microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain pri 1.8%
CVE-2011-0087 HIGH 7.2 microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka " 1.8%
CVE-2025-21172 HIGH 7.5 microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability 1.8%
CVE-2010-3957 HIGH 7.3 microsoft windows_2003_server Double free vulnerability in the OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted OpenTy 1.8%
CVE-2026-62888 HIGH 7.8 microsoft windows_10_21h2 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 1.8%
CVE-2026-62783 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. 1.8%
CVE-2010-0810 MED 4.7 microsoft windows_server_2008 The kernel in Microsoft Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, does not properly handle unspecified exceptions, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Excep 1.8%
CVE-2010-0235 MED 4.7 microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not perform the expected validation before creating a symbolic link, which allows local users to cause a denial of service (reboot) via a crafted application, aka "W 1.8%
CVE-2021-1717 MED 4.6 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 1.8%
CVE-2021-1641 MED 4.6 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 1.8%
CVE-2020-0924 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- 1.8%
CVE-2019-0936 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0734. 1.8%
CVE-2005-0545 HIGH 7.2 microsoft windows_2000 Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group policies that restrict access to hidden drives by using the browse feature in Office 10 applications such as Word or Excel, or using a flash dri 1.8%
CVE-2025-24035 HIGH 8.1 microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. 1.8%
CVE-2021-1728 HIGH 8.8 microsoft system_center_operations_manager System Center Operations Manager Elevation of Privilege Vulnerability 1.8%
CVE-2024-38104 HIGH 8.8 microsoft windows_10_1507 Windows Fax Service Remote Code Execution Vulnerability 1.8%
CVE-2023-35329 MED 6.5 microsoft windows_10_1507 Windows Authentication Denial of Service Vulnerability 1.8%
CVE-2024-26221 HIGH 7.2 microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability 1.8%
CVE-2018-8201 MED 4.5 microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 1.8%
CVE-2025-29968 MED 6.5 microsoft windows_server_2008 Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network. 1.8%