IT
56.707 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-60719 HIGH 7.0 microsoft windows_10_1607 Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 1.8%
CVE-1999-0505 HIGH 7.2 microsoft windows_2000 A Windows NT domain user or administrator account has a guessable password. 1.8%
CVE-2023-21741 HIGH 7.1 microsoft 365_apps Microsoft Office Visio Information Disclosure Vulnerability 1.8%
CVE-2015-1647 LOW 2.1 microsoft windows_8.1 Virtual Machine Manager (VMM) in Hyper-V in Microsoft Windows 8.1 and Windows Server 2012 R2 allows guest OS users to cause a denial of service (VMM functionality loss) via a crafted application, aka "Windows Hyper-V DoS Vulnerability." 1.8%
CVE-2025-21208 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.8%
CVE-2025-21201 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Server Remote Code Execution Vulnerability 1.8%
CVE-2025-21200 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.8%
CVE-2025-21190 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.8%
CVE-2022-30163 HIGH 8.5 microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability 1.8%
CVE-2010-3943 HIGH 7.2 microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly link driver objects, which allows local users to gain privileg 1.8%
CVE-2010-3942 HIGH 7.2 microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for copies from user mode, which allows local 1.8%
CVE-2020-1050 MED 6.1 microsoft dynamics_365_server A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. This 1.8%
CVE-2013-0076 HIGH 7.2 microsoft windows_7 The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Reference Count Vulne 1.8%
CVE-2012-1893 HIGH 7.2 microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate callback parameters during creation of a hook 1.8%
CVE-2012-1890 HIGH 7.2 microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle keyboard-layout files, which allows local users 1.8%
CVE-2023-35325 HIGH 7.5 microsoft windows_10_1507 Windows Print Spooler Information Disclosure Vulnerability 1.8%
CVE-1999-0549 HIGH 7.2 microsoft windows_nt Windows NT automatically logs in an administrator upon rebooting. 1.8%
CVE-2024-21428 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.8%
CVE-2024-21415 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.8%
CVE-2024-21373 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.8%
CVE-2024-21335 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.8%
CVE-2024-21333 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.8%
CVE-2024-21332 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.8%
CVE-2022-33647 HIGH 8.1 microsoft windows_server_2008 Windows Kerberos Elevation of Privilege Vulnerability 1.8%
CVE-2026-54121 HIGH 8.8 microsoft windows_10_1607 Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network. 1.8%