IT
56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.477 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-37324 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.6%
CVE-2024-37321 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.6%
CVE-2024-37320 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.6%
CVE-2024-35256 HIGH 8.8 microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability 1.6%
CVE-2000-0277 HIGH 7.2 microsoft excel Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability. 1.6%
CVE-2025-21225 MED 5.9 microsoft windows_server_2016 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability 1.6%
CVE-2024-30056 HIGH 7.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability 1.6%
CVE-2020-16940 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context.</p> <p>To exp 1.6%
CVE-2020-0694 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- 1.6%
CVE-2019-1261 HIGH 8.8 microsoft sharepoint_enterprise_server A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF).To exploit this vulnerability, an attacker would need to create a page specifically designed t 1.6%
CVE-2013-1293 MED 6.9 microsoft windows_7 The NTFS kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted applica 1.6%
CVE-2011-1282 HIGH 8.4 microsoft windows_2003_server The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly initial 1.6%
CVE-2026-27908 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally. 1.6%
CVE-2024-43622 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.6%
CVE-2024-43621 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.6%
CVE-2024-43620 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.6%
CVE-2023-21762 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability 1.6%
CVE-2025-33057 MED 6.5 microsoft windows_10_1507 Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network. 1.5%
CVE-2024-21369 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.5%
CVE-2022-35830 HIGH 8.1 microsoft windows_server_2008 Remote Procedure Call Runtime Remote Code Execution Vulnerability 1.5%
CVE-2007-2229 HIGH 7.2 microsoft windows_vista Microsoft Windows Vista uses insecure default permissions for unspecified "local user information data stores" in the registry and the file system, which allows local users to obtain sensitive information such as administrative passwords, aka "Permissive User 1.5%
CVE-2023-21563 MED 6.8 microsoft windows_10_1607 BitLocker Security Feature Bypass Vulnerability 1.5%
CVE-2019-1273 MED 5.4 microsoft windows_10 A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize certain error messages, aka 'Active Directory Federation Services XSS Vulnerability'. 1.5%
CVE-1999-0578 MED 4.6 microsoft windows_nt A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys. 1.5%
CVE-2022-41062 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 1.5%