IT
56.707 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2011-2011 HIGH 7.2 microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via 1.8%
CVE-2023-24954 MED 6.5 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Information Disclosure Vulnerability 1.8%
CVE-2023-36402 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.8%
CVE-2021-34451 MED 5.3 microsoft office_online_server Microsoft Office Online Server Spoofing Vulnerability 1.8%
CVE-2009-2517 MED 4.9 microsoft windows_server_2003 The kernel in Microsoft Windows Server 2003 SP2 does not properly handle unspecified exceptions when an error condition occurs, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vuln 1.8%
CVE-2023-38151 HIGH 8.8 microsoft host_integration_server Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability 1.8%
CVE-2023-36438 HIGH 7.5 microsoft windows_10_1507 Windows TCP/IP Information Disclosure Vulnerability 1.8%
CVE-2005-0061 HIGH 7.2 microsoft windows_2000 The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests. 1.8%
CVE-2024-43458 HIGH 7.7 microsoft windows_10_1607 Windows Networking Information Disclosure Vulnerability 1.8%
CVE-2024-38019 HIGH 7.2 microsoft windows_10_1507 Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability 1.8%
CVE-2011-0037 HIGH 7.2 microsoft forefront_client_security Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local use 1.8%
CVE-2023-35298 HIGH 7.5 microsoft windows_11_21h2 HTTP.sys Denial of Service Vulnerability 1.8%
CVE-2023-32084 HIGH 7.5 microsoft windows_10_1809 HTTP.sys Denial of Service Vulnerability 1.8%
CVE-2024-29045 HIGH 7.5 microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability 1.8%
CVE-2025-59214 MED 6.5 microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. 1.8%
CVE-2018-8549 MED 5.5 microsoft windows_10 A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 201 1.8%
CVE-2011-2002 MED 4.7 microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle TrueType fonts, which allows local users to cause a denial of service (system hang) via a crafted 1.8%
CVE-2010-0236 HIGH 7.2 microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not properly allocate memory for the destination key associated with a symbolic-link registry key, which allows local users to gain privileges via a crafted applicat 1.8%
CVE-2022-33673 MED 6.5 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 1.8%
CVE-2022-33672 MED 6.5 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 1.8%
CVE-2022-33666 MED 6.5 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 1.8%
CVE-2022-33665 MED 6.5 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 1.8%
CVE-2022-33663 MED 6.5 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 1.8%
CVE-2022-33662 MED 6.5 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 1.8%
CVE-2022-33661 MED 6.5 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 1.8%