56.761 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1490 | MED 5.4 | microsoft skype_for_business A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business Server Spoofing Vulnerability'. | 1.4% | — |
| CVE-2016-7238 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 mishandle caching for NTLM password-change requests, which al | 1.4% | — |
| CVE-2016-3254 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application | 1.4% | — |
| CVE-2016-3239 | HIGH 7.8 | microsoft windows_10 The Print Spooler service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via vectors involving | 1.4% | — |
| CVE-2001-0240 | MED 4.6 | microsoft word Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro. | 1.4% | — |
| CVE-2011-0638 | MED 6.9 | microsoft windows Microsoft Windows does not properly warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attackers to execute arbitrary programs via crafted USB data, as demonstrated by keyboard and mouse dat | 1.4% | — |
| CVE-2022-21899 | MED 5.5 | microsoft windows_10 Windows Extensible Firmware Interface Security Feature Bypass Vulnerability | 1.4% | — |
| CVE-2025-59247 | HIGH 8.8 | microsoft azure_playfab Azure PlayFab Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2020-0871 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when Windows Network Connections Service fails to properly handle objects in memory, aka 'Windows Network Connections Service Information Disclosure Vulnerability'. | 1.4% | — |
| CVE-2026-21520 | HIGH 7.5 | microsoft copilot_studio Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector | 1.4% | — |
| CVE-2024-49118 | HIGH 8.1 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2020-16951 | HIGH 8.6 | microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the ShareP | 1.4% | — |
| CVE-2010-1254 | MED 6.9 | microsoft open_xml_file_format_converter The installation for Microsoft Open XML File Format Converter for Mac sets insecure ACLs for the /Applications folder, which allows local users to execute arbitrary code by replacing the executable with a Trojan Horse, aka "Mac Office Open XML Permissions Vuln | 1.4% | — |
| CVE-2009-1126 | HIGH 7.2 | microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate the user-mode input associated with the editing of an unspecified desktop parameter, which allows local users to gain privileges via a crafted application, | 1.4% | — |
| CVE-2009-1125 | HIGH 7.2 | microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application | 1.4% | — |
| CVE-2009-1124 | HIGH 7.2 | microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate user-mode pointers in unspecified error conditions, which allows local users to gain privileges via a crafted ap | 1.4% | — |
| CVE-2026-21260 | HIGH 7.5 | microsoft 365_apps Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | 1.4% | — |
| CVE-2023-24858 | HIGH 7.5 | microsoft windows_10 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 1.4% | — |
| CVE-2023-21691 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulnerability | 1.4% | — |
| CVE-2022-22040 | HIGH 7.3 | microsoft windows_10 Internet Information Services Dynamic Compression Module Denial of Service Vulnerability | 1.4% | — |
| CVE-2019-0620 | HIGH 7.6 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a | 1.4% | — |
| CVE-2020-17035 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2020-0714 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Information Disclosure Vulnerability'. | 1.4% | — |
| CVE-2017-0099 | MED 5.4 | microsoft windows_10 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a de | 1.4% | — |
| CVE-2007-1220 | MED 6.2 | microsoft xbox_360 The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 does not properly verify the parameters passed to the syscall dispatcher, which allows attackers with physical access to bypass code-signing requirements and execute arbitrary code. | 1.4% | — |