IT
56.747 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.477 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2007-3463 MED 4.6 microsoft windows_xp Microsoft Windows XP SP2 allows local users, who have sessions created by another user's RunAs (run as) command, to kill arbitrary processes of this other user, as demonstrated by the taskkill program. NOTE: the researcher claims a vendor dispute in which the 1.5%
CVE-2022-30194 HIGH 7.5 microsoft windows_10 Windows WebBrowser Control Remote Code Execution Vulnerability 1.5%
CVE-2016-7292 HIGH 7.8 microsoft windows_10 The Installer in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 mishandles library loading, which allows loc 1.5%
CVE-2020-1289 MED 5.4 microsoft sharepoint_foundation A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1148. 1.5%
CVE-2002-1749 HIGH 7.2 microsoft windows_2000 Windows 2000 Terminal Services, when using the disconnect feature of the client, does not properly lock itself if it is left idle until the screen saver activates and the user disconnects, which could allow attackers to gain administrator privileges. 1.5%
CVE-2023-33143 HIGH 7.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.5%
CVE-2021-34485 MED 5.0 microsoft .net .NET Core and Visual Studio Information Disclosure Vulnerability 1.5%
CVE-2020-16901 MED 5.0 microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.</p> <p>To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploite 1.5%
CVE-2013-1287 HIGH 7.2 microsoft windows_7 The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which all 1.5%
CVE-2013-1286 HIGH 7.2 microsoft windows_7 The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which all 1.5%
CVE-2013-1285 HIGH 7.2 microsoft windows_7 The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which all 1.5%
CVE-2023-35303 HIGH 8.8 microsoft windows_10_1507 USB Audio Class System Driver Remote Code Execution Vulnerability 1.5%
CVE-2020-0736 MED 5.5 microsoft windows_7 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. 1.5%
CVE-2020-0717 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0716. 1.5%
CVE-2020-0716 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0717. 1.5%
CVE-2020-0705 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows Network Driver Interface Specification (NDIS) improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Network Dri 1.5%
CVE-2020-0698 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Telephony Service improperly discloses the contents of its memory, aka 'Windows Information Disclosure Vulnerability'. 1.5%
CVE-2020-0658 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'. 1.5%
CVE-2022-35743 HIGH 7.8 microsoft windows_10_1507 Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability 1.5%
CVE-2000-0199 HIGH 7.2 microsoft sql_server When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak encryption to store the login ID and password. 1.5%
CVE-2025-47954 HIGH 8.8 microsoft sql_server_2022 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 1.5%
CVE-2019-1474 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1472. 1.5%
CVE-2019-1472 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1474. 1.5%
CVE-2019-1381 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locations, aka 'Microsoft Windows Information Disclosure Vulnerability'. 1.5%
CVE-1999-0344 HIGH 7.2 microsoft windows_nt NT users can gain debug-level access on a system process using the Sechole exploit. 1.5%