IT
56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2011-1874 HIGH 7.8 microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain 1.2%
CVE-2023-21539 HIGH 7.5 microsoft windows_10_20h2 Windows Authentication Remote Code Execution Vulnerability 1.2%
CVE-2024-28899 HIGH 8.8 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 1.2%
CVE-2023-36037 HIGH 7.8 microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability 1.2%
CVE-2019-1211 HIGH 7.3 microsoft visual_studio_2017 An elevation of privilege vulnerability exists in Git for Visual Studio when it improperly parses configuration files. An attacker who successfully exploited the vulnerability could execute code in the context of another local user. To exploit the vulnerabilit 1.2%
CVE-2026-26105 HIGH 8.1 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 1.2%
CVE-2024-38263 HIGH 7.5 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability 1.2%
CVE-2026-20929 HIGH 7.5 microsoft windows_10_1607 Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. 1.2%
CVE-2025-26668 HIGH 7.5 microsoft windows_10_1507 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 1.2%
CVE-2020-1033 MED 4.0 microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>An authenticated 1.2%
CVE-2017-8579 HIGH 7.0 microsoft windows_10 The DirectX component in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to run arbitrary code in kernel mode via a specially crafted application, aka "DirectX Elevation of Privilege Vulnerability." 1.2%
CVE-2024-21396 HIGH 7.6 microsoft dynamics_365 Dynamics 365 Sales Spoofing Vulnerability 1.2%
CVE-2024-21393 HIGH 7.6 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 1.2%
CVE-2024-21389 HIGH 7.6 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 1.2%
CVE-2021-26862 HIGH 7.0 microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability 1.2%
CVE-2019-1088 HIGH 7.8 microsoft windows_10 An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1086, CVE-2019-1087. 1.2%
CVE-2019-1087 HIGH 7.8 microsoft windows_10 An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1086, CVE-2019-1088. 1.2%
CVE-2019-1086 HIGH 7.8 microsoft windows_10 An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1087, CVE-2019-1088. 1.2%
CVE-2019-1085 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the wlansvc.dll handles objects in memory, aka 'Windows WLAN Service Elevation of Privilege Vulnerability'. 1.2%
CVE-2025-49708 CRIT 9.9 microsoft windows_10_1809 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network. 1.2%
CVE-2025-54097 MED 6.5 microsoft windows_server_2008 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.2%
CVE-2025-54096 MED 6.5 microsoft windows_server_2008 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.2%
CVE-2025-54095 MED 6.5 microsoft windows_server_2008 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.2%
CVE-2025-53806 MED 6.5 microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.2%
CVE-2025-53798 MED 6.5 microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.2%