56.747 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2007-3463 | MED 4.6 | microsoft windows_xp Microsoft Windows XP SP2 allows local users, who have sessions created by another user's RunAs (run as) command, to kill arbitrary processes of this other user, as demonstrated by the taskkill program. NOTE: the researcher claims a vendor dispute in which the | 1.5% | — |
| CVE-2022-30194 | HIGH 7.5 | microsoft windows_10 Windows WebBrowser Control Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2016-7292 | HIGH 7.8 | microsoft windows_10 The Installer in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 mishandles library loading, which allows loc | 1.5% | — |
| CVE-2020-1289 | MED 5.4 | microsoft sharepoint_foundation A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1148. | 1.5% | — |
| CVE-2002-1749 | HIGH 7.2 | microsoft windows_2000 Windows 2000 Terminal Services, when using the disconnect feature of the client, does not properly lock itself if it is left idle until the screen saver activates and the user disconnects, which could allow attackers to gain administrator privileges. | 1.5% | — |
| CVE-2023-33143 | HIGH 7.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2021-34485 | MED 5.0 | microsoft .net .NET Core and Visual Studio Information Disclosure Vulnerability | 1.5% | — |
| CVE-2020-16901 | MED 5.0 | microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.</p> <p>To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploite | 1.5% | — |
| CVE-2013-1287 | HIGH 7.2 | microsoft windows_7 The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which all | 1.5% | — |
| CVE-2013-1286 | HIGH 7.2 | microsoft windows_7 The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which all | 1.5% | — |
| CVE-2013-1285 | HIGH 7.2 | microsoft windows_7 The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which all | 1.5% | — |
| CVE-2023-35303 | HIGH 8.8 | microsoft windows_10_1507 USB Audio Class System Driver Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2020-0736 | MED 5.5 | microsoft windows_7 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. | 1.5% | — |
| CVE-2020-0717 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0716. | 1.5% | — |
| CVE-2020-0716 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0717. | 1.5% | — |
| CVE-2020-0705 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Network Driver Interface Specification (NDIS) improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Network Dri | 1.5% | — |
| CVE-2020-0698 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Telephony Service improperly discloses the contents of its memory, aka 'Windows Information Disclosure Vulnerability'. | 1.5% | — |
| CVE-2020-0658 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'. | 1.5% | — |
| CVE-2022-35743 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2000-0199 | HIGH 7.2 | microsoft sql_server When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak encryption to store the login ID and password. | 1.5% | — |
| CVE-2025-47954 | HIGH 8.8 | microsoft sql_server_2022 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1.5% | — |
| CVE-2019-1474 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1472. | 1.5% | — |
| CVE-2019-1472 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1474. | 1.5% | — |
| CVE-2019-1381 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locations, aka 'Microsoft Windows Information Disclosure Vulnerability'. | 1.5% | — |
| CVE-1999-0344 | HIGH 7.2 | microsoft windows_nt NT users can gain debug-level access on a system process using the Sechole exploit. | 1.5% | — |