IT
56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.477 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-31964 HIGH 7.6 microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability 1.5%
CVE-2001-0005 MED 6.2 microsoft powerpoint Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands. 1.5%
CVE-2023-36018 HIGH 7.8 microsoft jupyter Visual Studio Code Jupyter Extension Spoofing Vulnerability 1.5%
CVE-2023-21676 HIGH 8.8 microsoft windows_10_1809 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 1.5%
CVE-2019-0931 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations, aka 'Windows Storage Service Elevation of Privilege Vulnerability'. 1.5%
CVE-2024-26192 HIGH 8.2 microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability 1.5%
CVE-2023-21525 MED 5.3 microsoft windows_10_1607 Remote Procedure Call Runtime Denial of Service Vulnerability 1.5%
CVE-1999-0534 MED 4.6 microsoft windows_2000 A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Increase Priority, Increase Quota, Load Driv 1.5%
CVE-2024-49125 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.5%
CVE-2024-49105 HIGH 8.4 microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability 1.5%
CVE-2024-21305 MED 4.4 microsoft windows_10_1809 Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability 1.5%
CVE-2020-1591 MED 5.4 microsoft dynamics_365 A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially cr 1.5%
CVE-2020-0891 MED 5.4 microsoft sharepoint_enterprise_server This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePo 1.5%
CVE-2004-2730 MED 4.6 microsoft psexec Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend 1.5%
CVE-2022-21891 HIGH 7.6 microsoft dynamics_365_sales Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability 1.5%
CVE-2022-21839 MED 6.1 microsoft windows_10 Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability 1.5%
CVE-2020-1377 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. A locally authenticated atta 1.5%
CVE-2024-26231 HIGH 7.2 microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability 1.5%
CVE-2024-26227 HIGH 7.2 microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability 1.5%
CVE-2002-1692 LOW 3.6 microsoft windows_95 Buffer overflow in backup utility of Microsoft Windows 95 allows attackers to execute arbitrary code by causing a filename with a long extension to be placed in a folder to be backed up. 1.5%
CVE-2025-27491 HIGH 7.1 microsoft windows_10_1507 Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network. 1.5%
CVE-2025-21380 HIGH 8.8 microsoft azure_marketplace Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network. 1.5%
CVE-2023-36873 HIGH 7.4 microsoft .net_framework .NET Framework Spoofing Vulnerability 1.5%
CVE-2025-21203 MED 6.5 microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.5%
CVE-2023-24881 MED 6.5 microsoft teams Microsoft Teams Information Disclosure Vulnerability 1.5%