IT
56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.477 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-21353 HIGH 8.8 microsoft windows_server_2022_23h2 Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability 1.6%
CVE-2022-23261 MED 5.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Tampering Vulnerability 1.6%
CVE-2020-0663 MED 4.2 microsoft edge An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacke 1.6%
CVE-2011-0043 HIGH 7.2 microsoft windows_2003_server Kerberos in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 supports weak hashing algorithms, which allows local users to gain privileges by operating a service that sends crafted service tickets, as demonstrated by the CRC32 algorithm, aka "Kerberos Unke 1.6%
CVE-2022-37972 HIGH 7.5 microsoft endpoint_configuration_manager Microsoft Endpoint Configuration Manager Spoofing Vulnerability 1.6%
CVE-2010-0026 MED 4.0 microsoft windows_server_2008 The Hyper-V server implementation in Microsoft Windows Server 2008 Gold, SP2, and R2 on the x64 platform allows guest OS users to cause a denial of service (host OS hang) via a crafted application that executes a malformed series of machine instructions, aka " 1.6%
CVE-2022-41127 HIGH 8.5 microsoft dynamics_365_business_central Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability 1.6%
CVE-2024-49082 MED 6.8 microsoft windows_10_1507 Windows File Explorer Information Disclosure Vulnerability 1.6%
CVE-2024-38214 MED 6.5 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability 1.6%
CVE-2021-28478 HIGH 7.6 microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability 1.6%
CVE-2023-23388 HIGH 8.8 microsoft windows_10_1507 Windows Bluetooth Driver Elevation of Privilege Vulnerability 1.6%
CVE-2018-8650 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoi 1.6%
CVE-2022-30170 HIGH 7.3 microsoft windows_10 Windows Credential Roaming Service Elevation of Privilege Vulnerability 1.6%
CVE-2020-1454 MED 5.4 microsoft sharepoint_enterprise_server This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePo 1.6%
CVE-2020-1326 MED 5.4 microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'. 1.6%
CVE-2017-8627 MED 4.7 microsoft windows_10 Windows Subsystem for Linux in Windows 10 1703, allows a denial of service vulnerability due to the way it handles objects in memory, aka "Windows Subsystem for Linux Denial of Service Vulnerability". 1.6%
CVE-2025-47172 HIGH 8.8 microsoft sharepoint_enterprise_server Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.6%
CVE-2025-21301 MED 6.5 microsoft windows_10_1507 Windows Geolocation Service Information Disclosure Vulnerability 1.6%
CVE-2019-0707 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it.To exploit the vulnerability, in a local attack scenario, an attacker could ru 1.6%
CVE-2017-8675 HIGH 7.0 microsoft windows_10 The Windows Kernel-Mode Drivers component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privil 1.6%
CVE-2023-35622 HIGH 7.5 microsoft windows_server_2008 Windows DNS Spoofing Vulnerability 1.6%
CVE-2017-0169 MED 5.4 microsoft windows_8.1 An information disclosure vulnerability exists when Windows Hyper-V running on a Windows 8.1, Windows Server 2012. or Windows Server 2012 R2 host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Hyp 1.6%
CVE-2016-0087 HIGH 7.8 microsoft windows_7 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 do not properly validate handles, which allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability." 1.6%
CVE-2025-33068 HIGH 7.5 microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. 1.6%
CVE-2025-32725 HIGH 7.5 microsoft windows_server_2016 Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. 1.6%