IT
56.761 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.477 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-41097 MED 6.7 microsoft windows_10_1809 Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 1.4%
CVE-2025-21314 MED 6.5 microsoft windows_10_1607 Windows SmartScreen Spoofing Vulnerability 1.4%
CVE-2022-26929 HIGH 7.8 microsoft .net_framework .NET Framework Remote Code Execution Vulnerability 1.4%
CVE-2020-16920 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.</p> <p>To exploit the 1.4%
CVE-2016-3349 HIGH 7.8 microsoft windows_10 The kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." 1.4%
CVE-2021-26871 HIGH 7.8 microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability 1.4%
CVE-2020-16992 HIGH 7.5 microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability 1.4%
CVE-2024-27099 CRIT 9.8 microsoft azure_uamqp The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect `AMQP_VALUE` failed state, may cause a double free problem. This may cause a RCE. Update submodule with commit 2ca42b6e4e098af2d17e487814a91d05f6ae4987. 1.4%
CVE-2010-1896 HIGH 8.4 microsoft windows_2003_server The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 do not properly validate user-mode input passed to kernel mode, which allows local users 1.4%
CVE-2025-24045 HIGH 8.1 microsoft windows_server_2012 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. 1.4%
CVE-2024-43589 HIGH 8.8 microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.4%
CVE-2016-7275 HIGH 7.8 microsoft office Microsoft Office 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vulnerability." 1.4%
CVE-2025-21306 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.4%
CVE-2025-21305 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.4%
CVE-2025-21303 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.4%
CVE-2025-21302 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.4%
CVE-2025-21252 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.4%
CVE-2024-43598 HIGH 8.1 microsoft lightgbm LightGBM Remote Code Execution Vulnerability 1.4%
CVE-2025-59259 MED 6.5 microsoft windows_10_1507 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. 1.4%
CVE-2025-59257 MED 6.5 microsoft windows_11_24h2 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. 1.4%
CVE-2024-43519 HIGH 8.8 microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.4%
CVE-2025-29960 MED 6.5 microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.4%
CVE-2025-29959 MED 6.5 microsoft windows_10_1507 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.4%
CVE-2021-26421 MED 6.5 microsoft lync_server Skype for Business and Lync Spoofing Vulnerability 1.4%
CVE-2017-8746 MED 5.3 microsoft windows_10 Windows Device Guard in Windows 10 1607, 1703, and Windows Server 2016 allows A security feature bypass vulnerability due to how PowerShell exposes functions and processes user supplied code, aka "Device Guard Security Feature Bypass Vulnerability". 1.4%