56.712 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-27482 | HIGH 8.1 | microsoft windows_server_2016 Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | 1.7% | — |
| CVE-2022-30215 | HIGH 7.5 | microsoft windows_server_2016 Active Directory Federation Services Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2023-36419 | HIGH 8.8 | microsoft azure_hdinsight Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2023-36907 | MED 5.5 | microsoft windows_10 Windows Cryptographic Services Information Disclosure Vulnerability | 1.7% | — |
| CVE-2023-36905 | MED 5.5 | microsoft windows_10 Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | 1.7% | — |
| CVE-2021-43214 | HIGH 7.8 | microsoft raw_image_extension Web Media Extensions Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2012-0005 | MED 6.9 | microsoft windows_server_2003 The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2, when a Chinese, Japanese, or Korean system locale is used, can access uninitialized memory during the | 1.7% | — |
| CVE-2023-28234 | HIGH 7.5 | microsoft windows_11_21h2 Windows Secure Channel Denial of Service Vulnerability | 1.7% | — |
| CVE-2023-28233 | HIGH 7.5 | microsoft windows_11_21h2 Windows Secure Channel Denial of Service Vulnerability | 1.7% | — |
| CVE-2026-50652 | HIGH 7.5 | microsoft .net_framework Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. | 1.7% | — |
| CVE-2024-21420 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2023-36407 | HIGH 7.8 | microsoft windows_11_21h2 Windows Hyper-V Elevation of Privilege Vulnerability | 1.7% | — |
| CVE-2020-1442 | MED 6.1 | microsoft office_online_server A spoofing vulnerability exists when an Office Web Apps server does not properly sanitize a specially crafted request, aka 'Office Web Apps XSS Vulnerability'. | 1.7% | — |
| CVE-2018-8417 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists in Microsoft JScript that could allow an attacker to bypass Device Guard, aka "Microsoft JScript Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 1 | 1.7% | — |
| CVE-2024-21380 | HIGH 8.0 | microsoft dynamics_365_business_central Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability | 1.7% | — |
| CVE-2020-16985 | MED 6.2 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 1.7% | — |
| CVE-2005-0060 | HIGH 7.2 | microsoft windows_2000 Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application. | 1.7% | — |
| CVE-2023-21543 | HIGH 8.1 | microsoft windows_10_1607 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2015-0084 | LOW 2.1 | microsoft windows_7 The Task Scheduler in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local users to bypass intended restri | 1.7% | — |
| CVE-2013-2553 | HIGH 7.2 | microsoft windows_7 Unspecified vulnerability in the kernel in Microsoft Windows 7 allows local users to gain privileges via unknown vectors, as demonstrated by Nils and Jon of MWR Labs during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0912. | 1.7% | — |
| CVE-2022-35767 | HIGH 8.1 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2022-35766 | HIGH 8.1 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2013-1280 | HIGH 7.2 | microsoft windows_7 The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows | 1.7% | — |
| CVE-2012-1866 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver | 1.7% | — |
| CVE-2019-0928 | MED 6.2 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. | 1.7% | — |