56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-7260 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileg | 1.6% | — |
| CVE-2011-0662 | HIGH 7.2 | microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain | 1.6% | — |
| CVE-2024-26233 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-26224 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-26223 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2021-31184 | MED 5.5 | microsoft windows_10 Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability | 1.6% | — |
| CVE-2019-1375 | MED 5.4 | microsoft dynamics_365 A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. | 1.6% | — |
| CVE-2019-0876 | MED 5.5 | microsoft open_enclave_software_development_kit An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'. | 1.6% | — |
| CVE-2024-21302 | MED 6.7 | microsoft windows_10_1507 Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to | 1.6% | — |
| CVE-2023-35384 | MED 5.4 | microsoft windows_10_1507 Windows HTML Platforms Security Feature Bypass Vulnerability | 1.6% | — |
| CVE-2023-24936 | HIGH 7.5 | microsoft .net .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | 1.6% | — |
| CVE-2022-23256 | HIGH 8.1 | microsoft azure_data_explorer Azure Data Explorer Spoofing Vulnerability | 1.6% | — |
| CVE-2025-27472 | MED 5.4 | microsoft windows_10_1507 Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network. | 1.6% | — |
| CVE-2023-35321 | MED 6.5 | microsoft windows_server_2008 Windows Deployment Services Denial of Service Vulnerability | 1.6% | — |
| CVE-2015-6126 | HIGH 7.2 | microsoft windows_10 Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 | 1.6% | — |
| CVE-1999-0701 | HIGH 7.2 | microsoft windows_nt After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password. | 1.6% | — |
| CVE-1999-0839 | HIGH 7.2 | microsoft ie Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled. | 1.6% | — |
| CVE-2019-0996 | MED 6.5 | microsoft azure_devops_server A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery. An attacker who successfully exploited this vulnerability could bypass OAuth protections and regist | 1.6% | — |
| CVE-2025-55241 | CRIT 10.0 | microsoft entra_id Azure Entra ID Elevation of Privilege Vulnerability | 1.6% | — |
| CVE-2024-47083 | HIGH 7.5 | microsoft power_platform_terraform_provider Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior to 3.0.0 have an issue in the Power Platform Terraform Provider where sensitive information, specifically the `client_secret` used in the s | 1.6% | — |
| CVE-2024-38049 | MED 6.6 | microsoft windows_10_1507 Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37333 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37330 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37329 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37328 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |