56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-17010 | HIGH 7.8 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2019-1362 | HIGH 7.8 | microsoft windows_7 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1364. | 1.5% | — |
| CVE-2019-1202 | MED 4.4 | microsoft sharepoint_enterprise_server An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker who successfully exploited the vulnerability could hijack the session of another user. To exploit this vulnerability, the attacker | 1.5% | — |
| CVE-2026-66805 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.5% | — |
| CVE-2020-0795 | MED 5.4 | microsoft business_productivity_servers This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePo | 1.5% | — |
| CVE-2009-2513 | HIGH 7.2 | microsoft windows_2000 The Graphics Device Interface (GDI) in win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain | 1.5% | — |
| CVE-2009-1127 | HIGH 7.2 | microsoft windows_2000 win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not correctly validate an argument to an unspecified system call, which allows local users to gain privileges v | 1.5% | — |
| CVE-2009-2515 | HIGH 7.2 | microsoft windows_2000 Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application that triggers an incorrect truncation of a 64 | 1.5% | — |
| CVE-2024-45383 | MED 5.0 | microsoft high_definition_audio_bus_driver A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.3636 (WinBuild.160101.0800). A specially crafted application can issue multiple IRP Complete requests which leads to a loc | 1.5% | — |
| CVE-2008-2143 | LOW 1.9 | microsoft outlook_web_access Unspecified versions of Microsoft Outlook Web Access (OWA) use the Cache-Control: no-cache HTTP directive instead of no-store, which might cause web browsers that follow RFC-2616 to cache sensitive information. | 1.5% | — |
| CVE-2025-54100 | HIGH 7.8 | microsoft windows_10_1607 Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally. | 1.5% | — |
| CVE-2024-30024 | HIGH 7.5 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2024-30023 | HIGH 7.5 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2024-30022 | HIGH 7.5 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2018-8142 | MED 5.3 | microsoft windows_10 A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1035. | 1.5% | — |
| CVE-2026-20875 | HIGH 7.5 | microsoft windows_10_1607 Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | 1.5% | — |
| CVE-2017-8557 | MED 5.5 | microsoft windows_10 Windows System Information Console in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability imp | 1.5% | — |
| CVE-2025-26682 | HIGH 7.5 | microsoft asp.net_core Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | 1.5% | — |
| CVE-2022-37975 | HIGH 8.8 | microsoft windows_10 Windows Group Policy Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2024-49018 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2022-33637 | MED 6.5 | microsoft defender_for_endpoint Microsoft Defender for Endpoint Tampering Vulnerability | 1.5% | — |
| CVE-2018-8170 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory, aka "Windows Image Elevation of Privilege Vulnerability." This affects Windows 10, Windows 10 Servers. | 1.5% | — |
| CVE-2022-44684 | MED 6.5 | microsoft windows_10_20h2 Windows Local Session Manager (LSM) Denial of Service Vulnerability | 1.5% | — |
| CVE-2013-1254 | MED 4.9 | microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently | 1.5% | — |
| CVE-2017-0077 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow a local authenticated attacker to execute a specially c | 1.5% | — |