56.736 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.474 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-28243 | HIGH 8.8 | microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2020-1325 | MED 5.4 | microsoft azure_devops_server Azure DevOps Server and Team Foundation Services Spoofing Vulnerability | 1.6% | — |
| CVE-2020-1575 | MED 5.4 | microsoft sharepoint_foundation <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially | 1.6% | — |
| CVE-2020-16878 | MED 5.4 | microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially | 1.6% | — |
| CVE-2020-16871 | MED 5.4 | microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially | 1.6% | — |
| CVE-2020-16859 | MED 5.4 | microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially | 1.6% | — |
| CVE-2020-16858 | MED 5.4 | microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially | 1.6% | — |
| CVE-2017-0178 | MED 5.4 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V running on Windows 10, Windows 10 1511, Windows 10 1607, Windows 8.1, Windows Server 2012 R2, and Windows Server 2016 host server fails to properly validate input from a privileged user on a guest | 1.6% | — |
| CVE-2025-21313 | MED 6.5 | microsoft windows_11_24h2 Windows Security Account Manager (SAM) Denial of Service Vulnerability | 1.6% | — |
| CVE-2021-40457 | HIGH 7.4 | microsoft dynamics_365 Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability | 1.6% | — |
| CVE-2024-43591 | HIGH 8.7 | microsoft azure_command-line_interface Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability | 1.6% | — |
| CVE-2020-0661 | MED 6.8 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-075 | 1.6% | — |
| CVE-2019-1082 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows where a certain DLL, with Local Service privilege, is vulnerable to race planting a customized DLL.An attacker who successfully exploited this vulnerability could potentially elevate privilege | 1.6% | — |
| CVE-2023-33173 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-33172 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-33169 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-33168 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-33167 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-33166 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-32035 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-32034 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2026-45454 | MED 6.5 | microsoft sharepoint_server Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.6% | — |
| CVE-2026-25166 | HIGH 7.8 | microsoft windows_10_1607 Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally. | 1.6% | — |
| CVE-2023-35319 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |
| CVE-2023-35318 | MED 6.5 | microsoft windows_10_1507 Remote Procedure Call Runtime Denial of Service Vulnerability | 1.6% | — |