IT
56.727 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.472 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-35416 HIGH 7.0 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 1.6%
CVE-2020-17048 MED 4.2 microsoft chakracore Chakra Scripting Engine Memory Corruption Vulnerability 1.6%
CVE-2025-21242 MED 5.9 microsoft windows_10_1507 Windows Kerberos Information Disclosure Vulnerability 1.6%
CVE-2024-37334 HIGH 8.8 microsoft ole_db_driver_for_sql_server Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability 1.6%
CVE-2012-1894 MED 6.9 microsoft office Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, which allows local users to gain privileges by placing a Trojan horse executable file in one of these directori 1.6%
CVE-2025-27474 MED 6.5 microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.6%
CVE-2025-26672 MED 6.5 microsoft windows_10_1507 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.6%
CVE-2025-26667 MED 6.5 microsoft windows_server_2008 Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.6%
CVE-2025-26664 MED 6.5 microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.6%
CVE-2024-21368 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.6%
CVE-2024-21361 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.6%
CVE-2024-21359 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.6%
CVE-2024-21349 HIGH 8.8 microsoft windows_10_1507 Microsoft ActiveX Data Objects Remote Code Execution Vulnerability 1.6%
CVE-2022-24485 HIGH 7.5 microsoft windows_10 Win32 File Enumeration Remote Code Execution Vulnerability 1.6%
CVE-2017-8720 HIGH 7.8 microsoft windows_10 The Microsoft Windows graphics component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privile 1.6%
CVE-2019-0733 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'. 1.6%
CVE-2018-8219 HIGH 8.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows Hyper-V instruction emulation fails to properly enforce privilege levels, aka "Hypervisor Code Integrity Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 1.6%
CVE-2021-26443 CRIT 9.0 microsoft windows_10 Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability 1.6%
CVE-2020-16994 HIGH 7.3 microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability 1.6%
CVE-2019-0966 MED 6.8 microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. 1.6%
CVE-2015-0012 MED 6.9 microsoft virtual_machine_manager Microsoft System Center Virtual Machine Manager (VMM) 2012 R2 Update Rollup 4 does not properly validate the roles of users, which allows local users to obtain server and virtual-machine administrative privileges by establishing a server session with Active Di 1.6%
CVE-2022-38033 MED 6.5 microsoft windows_10 Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability 1.6%
CVE-2020-1191 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit 1.6%
CVE-2010-3940 HIGH 7.2 microsoft windows_2003_server Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted 1.6%
CVE-2007-2999 LOW 1.8 microsoft windows_2003_server Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers to det 1.6%