Microsoft Vulnerabilities
Microsoft makes the Windows operating system, the Edge browser and Microsoft 365, along with on-premises server products such as Exchange Server and SharePoint Server. The database tracks 394 Microsoft CVE records. CISA lists 389 of them as exploited in the wild, most recently on 2026-09-25. The most affected products are Windows, Internet Explorer, Office.
Recently Exploited Microsoft CVEs
Microsoft SharePoint Server Remote Code Execution Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Update Stack Elevation of Privilege Vulnerability
Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
Affected Products
74 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| Windows | 172 | 172 | 2026-09-08 |
| Internet Explorer | 36 | 36 | 2026-05-20 |
| Office | 29 | 29 | 2026-04-14 |
| Win32k | 25 | 25 | 2023-06-22 |
| Exchange Server | 17 | 17 | 2026-04-13 |
| SharePoint | 10 | 10 | 2026-09-25 |
| Defender | 5 | 5 | 2026-05-20 |
| SharePoint Server | 5 | 5 | 2026-07-14 |
| Open Management Infrastructure (OMI) | 4 | 4 | 2021-11-03 |
| Word | 4 | 4 | 2023-09-12 |
| .NET Framework | 3 | 3 | 2025-02-04 |
| Active Directory | 3 | 3 | 2022-08-18 |
| Excel | 3 | 3 | 2022-03-03 |
| Silverlight | 3 | 3 | 2022-05-25 |
| Windows 10 Version 1607 | 3 | - | 2026-02-10 |
| DirectX Graphics Kernel (DXGKRNL) | 2 | 2 | 2022-03-28 |
| Edge | 2 | 2 | 2022-03-28 |
| Edge and Internet Explorer | 2 | 2 | 2022-03-28 |
| Enhanced Cryptographic Provider | 2 | 2 | 2021-11-03 |
| Graphics Device Interface (GDI) | 2 | 2 | 2022-03-25 |
| Microsoft SharePoint Enterprise Server 2016 | 2 | - | 2026-04-14 |
| MSHTML | 2 | 2 | 2021-11-03 |
| PowerPoint | 2 | 2 | 2022-06-08 |
| SMBv1 | 2 | 2 | 2022-02-10 |
| SMBv1 server | 2 | 2 | 2022-05-24 |
| SQL Server | 2 | 2 | 2026-08-26 |
| Windows | 2 | 2 | 2024-10-15 |
| XML Core Services | 2 | 2 | 2022-06-08 |
| .NET Core and Visual Studio | 1 | 1 | 2023-08-09 |
| .NET Framework, SharePoint, Visual Studio | 1 | 1 | 2021-11-03 |
| Active Directory Federation Services | 1 | 1 | 2026-07-14 |
| Ancillary Function Driver (afd.sys) | 1 | 1 | 2022-03-28 |
| ATM Font Driver | 1 | 1 | 2022-03-03 |
| Client-Server Run-time Subsystem (CSRSS) | 1 | 1 | 2022-03-28 |
| Configuration Manager | 1 | 1 | 2026-02-12 |
| DirectX | 1 | 1 | 2026-05-20 |
| DWM Core Library | 1 | 1 | 2024-05-14 |
| Exchange | 1 | 1 | 2021-11-17 |
| Forefront Threat Management Gateway (TMG) | 1 | 1 | 2022-03-03 |
| Graphics Component | 1 | 1 | 2022-02-15 |
| HTTP Protocol Stack | 1 | 1 | 2022-04-06 |
| HTTP.sys | 1 | 1 | 2022-02-10 |
| Hyper-V RemoteFX | 1 | 1 | 2021-11-03 |
| Input Method Editor (IME) Japanese | 1 | 1 | 2022-05-25 |
| Internet Explorer and Edge | 1 | 1 | 2022-05-24 |
| Internet Explorer Scripting Engine | 1 | 1 | 2022-03-25 |
| Internet Information Services (IIS) | 1 | 1 | 2021-11-03 |
| Internet Key Exchange (IKE) Service Extensions | 1 | 1 | 2026-08-18 |
| Kerberos Key Distribution Center (KDC) | 1 | 1 | 2022-03-25 |
| Malware Protection Engine | 1 | 1 | 2022-03-03 |
| Microsoft | 1 | 1 | 2026-05-15 |
| MSCOMCTL.OCX | 1 | 1 | 2021-11-03 |
| Netlogon | 1 | 1 | 2021-11-03 |
| Office and WordPad | 1 | 1 | 2021-11-03 |
| Office Outlook | 1 | 1 | 2025-02-06 |
| Outlook | 1 | 1 | 2023-07-11 |
| Partner Center | 1 | 1 | 2025-02-25 |
| Power Pages | 1 | 1 | 2025-02-21 |
| Project | 1 | 1 | 2024-08-13 |
| Publisher | 1 | 1 | 2024-09-10 |
| Remote Desktop Services | 1 | 1 | 2021-11-03 |
| Skype for Business | 1 | 1 | 2023-10-10 |
| SmartScreen Prompt | 1 | 1 | 2024-04-30 |
| SMBv3 | 1 | 1 | 2022-02-10 |
| Streaming Service | 1 | 1 | 2024-02-29 |
| Streaming Service Proxy | 1 | 1 | 2023-09-12 |
| Task Scheduler | 1 | 1 | 2022-03-15 |
| Update Notification Manager | 1 | 1 | 2022-05-23 |
| Visual Basic for Applications (VBA) | 1 | 1 | 2026-04-13 |
| Windows Ancillary Function Driver for WinSock | 1 | 1 | 2026-08-11 |
| Windows CNG Key Isolation Service | 1 | 1 | 2023-10-04 |
| Windows COM+ Event System Service | 1 | 1 | 2022-10-11 |
| WinVerifyTrust function | 1 | 1 | 2022-01-10 |
| WordPad | 1 | 1 | 2023-10-10 |
All Microsoft CVEs
394 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-65660 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Microsoft | 8.8 | 2.1% | KEV | 2026-08-11 |
| CVE-2026-85880 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | Microsoft | 7.8 | 3.6% | KEV | 2026-09-08 |
| CVE-2026-81963 | Windows Update Stack Elevation of Privilege Vulnerability | Microsoft | 7.8 | 0.4% | KEV | 2026-09-08 |
| CVE-2019-1068 | Microsoft SQL Server Remote Code Execution Vulnerability | Microsoft | 8.8 | 57.3% | KEV | 2019-07-15 |
| CVE-2026-55040 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | Microsoft | 9.1 | 69.5% | KEV | 2026-07-14 |
| CVE-2026-33824 | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability | Microsoft | 9.8 | 1.6% | KEV | 2026-04-14 |
| CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Microsoft | 7.0 | 0.3% | KEV | 2026-08-11 |
| CVE-2026-50522 | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft | 9.8 | 3.0% | KEV | 2026-07-14 |
| CVE-2026-58644 | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft | 9.8 | 15.9% | KEV | 2026-07-14 |
| CVE-2026-56164 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | Microsoft | 5.3 | 1.0% | KEV | 2026-07-14 |
| CVE-2026-56155 | Active Directory Federation Services Elevation of Privilege Vulnerability | Microsoft | 7.8 | 0.3% | KEV | 2026-07-14 |
| CVE-2026-45659 | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft | 8.8 | 2.7% | KEV | 2026-05-22 |
| CVE-2008-4250 | Microsoft Windows Buffer Overflow Vulnerability | - | 9.8 | 98.8% | KEV | 2008-10-23 |
| CVE-2010-0249 | Microsoft Internet Explorer Use-After-Free Vulnerability | - | 8.8 | 91.9% | KEV | 2010-01-15 |
| CVE-2010-0806 | Microsoft Internet Explorer Use-After-Free Vulnerability | - | 8.8 | 82.2% | KEV | 2010-03-10 |
| CVE-2009-1537 | Microsoft DirectX NULL Byte Overwrite Vulnerability | - | 8.8 | 51.2% | KEV | 2009-05-29 |
| CVE-2026-45498 | Microsoft Defender Denial of Service Vulnerability | Microsoft | 4.0 | 1.3% | KEV | 2026-05-20 |
| CVE-2026-41091 | Microsoft Defender Elevation of Privilege Vulnerability | Microsoft | 7.8 | 0.4% | KEV | 2026-05-20 |
| CVE-2026-42897 | Microsoft Exchange Server Spoofing Vulnerability | Microsoft | 8.1 | 0.5% | KEV | 2026-05-14 |
| CVE-2026-32202 | Windows Shell Spoofing Vulnerability | Microsoft | 4.3 | 4.9% | KEV | 2026-04-14 |
| CVE-2026-33825 | Microsoft Defender Elevation of Privilege Vulnerability | Microsoft | 7.8 | 0.4% | KEV | 2026-04-14 |
| CVE-2026-32201 | Microsoft SharePoint Server Spoofing Vulnerability | Microsoft | 6.5 | 43.4% | KEV | 2026-04-14 |
| CVE-2009-0238 | Microsoft Office Remote Code Execution | - | 8.8 | 43.2% | KEV | 2009-02-25 |
| CVE-2023-21529 | Microsoft Exchange Server Remote Code Execution Vulnerability | Microsoft | 8.8 | 59.3% | KEV | 2023-02-14 |
| CVE-2012-1854 | Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability | - | 7.8 | 21.0% | KEV | 2012-07-10 |
| CVE-2023-36424 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 12.2% | KEV | 2023-11-14 |
| CVE-2025-60710 | Host Process for Windows Tasks Elevation of Privilege Vulnerability | Microsoft | 7.8 | 4.6% | KEV | 2025-11-11 |
| CVE-2026-20963 | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft | 9.8 | 29.6% | KEV | 2026-01-13 |
| CVE-2008-0015 | Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability | - | 8.8 | 76.6% | KEV | 2009-07-07 |
| CVE-2024-43468 | Microsoft Configuration Manager Remote Code Execution Vulnerability | Microsoft | 9.8 | 81.0% | KEV | 2024-10-08 |
| CVE-2026-21510 | Windows Shell Security Feature Bypass Vulnerability | Microsoft | 8.8 | 24.5% | KEV | 2026-02-10 |
| CVE-2026-21513 | MSHTML Framework Security Feature Bypass Vulnerability | Microsoft | 8.8 | 15.9% | KEV | 2026-02-10 |
| CVE-2026-21525 | Windows Remote Access Connection Manager Denial of Service Vulnerability | Microsoft | 6.2 | 4.9% | KEV | 2026-02-10 |
| CVE-2026-21533 | Windows Remote Desktop Services Elevation of Privilege Vulnerability | Microsoft | 7.8 | 4.2% | KEV | 2026-02-10 |
| CVE-2026-21519 | Desktop Window Manager Elevation of Privilege Vulnerability | Microsoft | 7.8 | 2.5% | KEV | 2026-02-10 |
| CVE-2026-21514 | Microsoft Word Security Feature Bypass Vulnerability | Microsoft | 7.8 | 1.6% | KEV | 2026-02-10 |
| CVE-2026-21509 | Microsoft Office Security Feature Bypass Vulnerability | Microsoft | 7.8 | 70.8% | KEV | 2026-01-26 |
| CVE-2026-20805 | Desktop Window Manager Information Disclosure Vulnerability | Microsoft | 5.5 | 7.2% | KEV | 2026-01-13 |
| CVE-2009-0556 | Microsoft Office PowerPoint Code Injection Vulnerability | - | 8.8 | 67.3% | KEV | 2009-04-03 |
| CVE-2025-62221 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 2.5% | KEV | 2025-12-09 |
| CVE-2025-62215 | Windows Kernel Elevation of Privilege Vulnerability | Microsoft | 7.0 | 6.0% | KEV | 2025-11-11 |
| CVE-2025-59287 | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability | Microsoft | 9.8 | 100.0% | KEV | 2025-10-14 |
| CVE-2025-33073 | Windows SMB Client Elevation of Privilege Vulnerability | Microsoft | 8.8 | 82.7% | KEV | 2025-06-10 |
| CVE-2025-24990 | Windows Agere Modem Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 6.4% | KEV | 2025-10-14 |
| CVE-2025-59230 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Microsoft | 7.8 | 2.7% | KEV | 2025-10-14 |
| CVE-2010-3962 | Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability | - | 8.1 | 96.8% | KEV | 2010-11-05 |
| CVE-2011-3402 | Microsoft Windows Remote Code Execution Vulnerability | - | 8.8 | 78.1% | KEV | 2011-11-04 |
| CVE-2013-3918 | Microsoft Windows Out-of-Bounds Write Vulnerability | - | 8.8 | 73.7% | KEV | 2013-11-12 |
| CVE-2021-43226 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 3.3% | KEV | 2021-12-15 |
| CVE-2013-3893 | Microsoft Internet Explorer Resource Management Errors Vulnerability | - | 8.8 | 87.5% | KEV | 2013-09-18 |
| CVE-2007-0671 | Microsoft Office Excel Remote Code Execution Vulnerability | - | 8.8 | 43.2% | KEV | 2007-02-03 |
| CVE-2025-49704 | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft | 8.8 | 100.0% | KEV | 2025-07-08 |
| CVE-2025-49706 | Microsoft SharePoint Server Spoofing Vulnerability | Microsoft | 6.5 | 99.1% | KEV | 2025-07-08 |
| CVE-2025-53770 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Microsoft | 9.8 | 100.0% | KEV | 2025-07-20 |
| CVE-2025-33053 | Internet Shortcut Files Remote Code Execution Vulnerability | Microsoft | 8.8 | 87.0% | KEV | 2025-06-10 |
| CVE-2025-30397 | Scripting Engine Memory Corruption Vulnerability | Microsoft | 7.5 | 26.8% | KEV | 2025-05-13 |
| CVE-2025-32706 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 2.3% | KEV | 2025-05-13 |
| CVE-2025-32709 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Microsoft | 7.8 | 2.2% | KEV | 2025-05-13 |
| CVE-2025-30400 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.9% | KEV | 2025-05-13 |
| CVE-2025-32701 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.4% | KEV | 2025-05-13 |
| CVE-2025-24054 | NTLM Hash Disclosure Spoofing Vulnerability | Microsoft | 6.5 | 58.9% | KEV | 2025-03-11 |
| CVE-2025-29824 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 13.9% | KEV | 2025-04-08 |
| CVE-2025-26633 | Microsoft Management Console Security Feature Bypass Vulnerability | Microsoft | 7.0 | 30.4% | KEV | 2025-03-11 |
| CVE-2025-24985 | Windows Fast FAT File System Driver Remote Code Execution Vulnerability | Microsoft | 7.8 | 3.9% | KEV | 2025-03-11 |
| CVE-2025-24993 | Windows NTFS Remote Code Execution Vulnerability | Microsoft | 7.8 | 2.2% | KEV | 2025-03-11 |
| CVE-2025-24991 | Windows NTFS Information Disclosure Vulnerability | Microsoft | 5.5 | 2.0% | KEV | 2025-03-11 |
| CVE-2025-24984 | Windows NTFS Information Disclosure Vulnerability | Microsoft | 4.6 | 2.0% | KEV | 2025-03-11 |
| CVE-2025-24983 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | Microsoft | 7.0 | 1.4% | KEV | 2025-03-11 |
| CVE-2018-8639 | Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability | Microsoft | 8.4 | 22.2% | KEV | 2018-12-12 |
| CVE-2024-49035 | Partner.Microsoft.Com Elevation of Privilege Vulnerability | Microsoft | 8.7 | 1.3% | KEV | 2024-11-26 |
| CVE-2025-24989 | Microsoft Power Pages Elevation of Privilege Vulnerability | Microsoft | 8.2 | 1.6% | KEV | 2025-02-19 |
| CVE-2025-21391 | Windows Storage Elevation of Privilege Vulnerability | Microsoft | 7.1 | 2.3% | KEV | 2025-02-11 |
| CVE-2025-21418 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.6% | KEV | 2025-02-11 |
| CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability | Microsoft | 9.8 | 94.7% | KEV | 2024-02-13 |
| CVE-2024-29059 | .NET Framework Information Disclosure Vulnerability | Microsoft | 7.5 | 98.6% | KEV | 2024-03-22 |
| CVE-2025-21333 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Microsoft | 7.8 | 10.0% | KEV | 2025-01-14 |
| CVE-2025-21334 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.6% | KEV | 2025-01-14 |
| CVE-2025-21335 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.4% | KEV | 2025-01-14 |
| CVE-2024-35250 | Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 25.2% | KEV | 2024-06-11 |
| CVE-2024-49138 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 26.2% | KEV | 2024-12-10 |
| CVE-2024-43451 | NTLM Hash Disclosure Spoofing Vulnerability | Microsoft | 6.5 | 84.1% | KEV | 2024-11-12 |
| CVE-2024-49039 | Windows Task Scheduler Elevation of Privilege Vulnerability | Microsoft | 8.8 | 14.2% | KEV | 2024-11-12 |
| CVE-2024-38094 | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft | 7.2 | 50.9% | KEV | 2024-07-09 |
| CVE-2024-30088 | Windows Kernel Elevation of Privilege Vulnerability | Microsoft | 7.0 | 68.2% | KEV | 2024-06-11 |
| CVE-2024-43572 | Microsoft Management Console Remote Code Execution Vulnerability | Microsoft | 7.8 | 66.7% | KEV | 2024-10-08 |
| CVE-2024-43573 | Windows MSHTML Platform Spoofing Vulnerability | Microsoft | 6.5 | 46.1% | KEV | 2024-10-08 |
| CVE-2020-0618 | Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability | Microsoft | 9.8 | 99.0% | KEV | 2020-02-11 |
| CVE-2024-43461 | Windows MSHTML Platform Spoofing Vulnerability | Microsoft | 8.8 | 54.5% | KEV | 2024-09-10 |
| CVE-2024-38217 | Windows Mark of the Web Security Feature Bypass Vulnerability | Microsoft | 5.4 | 10.0% | KEV | 2024-09-10 |
| CVE-2024-38014 | Windows Installer Elevation of Privilege Vulnerability | Microsoft | 7.8 | 6.3% | KEV | 2024-09-10 |
| CVE-2024-38226 | Microsoft Publisher Security Feature Bypass Vulnerability | Microsoft | 7.3 | 2.7% | KEV | 2024-09-10 |
| CVE-2021-31196 | Microsoft Exchange Server Remote Code Execution Vulnerability | Microsoft | 7.2 | 54.1% | KEV | 2021-07-14 |
| CVE-2024-38178 | Scripting Engine Memory Corruption Vulnerability | Microsoft | 7.5 | 41.4% | KEV | 2024-08-13 |
| CVE-2024-38193 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Microsoft | 7.8 | 28.7% | KEV | 2024-08-13 |
| CVE-2024-38213 | Windows Mark of the Web Security Feature Bypass Vulnerability | Microsoft | 6.5 | 13.6% | KEV | 2024-08-13 |
| CVE-2024-38189 | Microsoft Project Remote Code Execution Vulnerability | Microsoft | 8.8 | 8.2% | KEV | 2024-08-13 |
| CVE-2024-38106 | Windows Kernel Elevation of Privilege Vulnerability | Microsoft | 7.0 | 6.3% | KEV | 2024-08-13 |
| CVE-2024-38107 | Windows Power Dependency Coordinator Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.6% | KEV | 2024-08-13 |
| CVE-2018-0824 | Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability | - | 7.5 | 73.2% | KEV | 2018-05-09 |
| CVE-2012-4792 | Microsoft Internet Explorer Use-After-Free Vulnerability | - | 8.8 | 78.8% | KEV | 2012-12-30 |
| CVE-2024-38112 | Windows MSHTML Platform Spoofing Vulnerability | Microsoft | 7.5 | 84.2% | KEV | 2024-07-09 |
| CVE-2024-38080 | Windows Hyper-V Elevation of Privilege Vulnerability | Microsoft | 7.8 | 7.1% | KEV | 2024-07-09 |
| CVE-2024-26169 | Windows Error Reporting Service Elevation of Privilege Vulnerability | Microsoft | 7.8 | 4.0% | KEV | 2024-03-12 |
| CVE-2024-30051 | Windows DWM Core Library Elevation of Privilege Vulnerability | Microsoft | 7.8 | 5.7% | KEV | 2024-05-14 |
| CVE-2024-30040 | Windows MSHTML Platform Security Feature Bypass Vulnerability | Microsoft | 8.8 | 3.9% | KEV | 2024-05-14 |
| CVE-2024-29988 | SmartScreen Prompt Security Feature Bypass Vulnerability | Microsoft | 8.8 | 44.9% | KEV | 2024-04-09 |
| CVE-2022-38028 | Windows Print Spooler Elevation of Privilege Vulnerability | Microsoft | 7.8 | 14.9% | KEV | 2022-10-11 |
| CVE-2023-24955 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Microsoft | 7.2 | 85.0% | KEV | 2023-05-09 |
| CVE-2024-21338 | Windows Kernel Elevation of Privilege Vulnerability | Microsoft | 7.8 | 59.8% | KEV | 2024-02-13 |
| CVE-2023-29360 | Microsoft Streaming Service Elevation of Privilege Vulnerability | Microsoft | 8.4 | 21.6% | KEV | 2023-06-13 |
| CVE-2024-21410 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Microsoft | 9.8 | 12.6% | KEV | 2024-02-13 |
| CVE-2024-21412 | Internet Shortcut Files Security Feature Bypass Vulnerability | Microsoft | 8.1 | 99.4% | KEV | 2024-02-13 |
| CVE-2024-21351 | Windows SmartScreen Security Feature Bypass Vulnerability | Microsoft | 7.6 | 27.8% | KEV | 2024-02-13 |
| CVE-2023-29357 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | Microsoft | 9.8 | 100.0% | KEV | 2023-06-13 |
| CVE-2023-36584 | Windows Mark of the Web Security Feature Bypass Vulnerability | Microsoft | 5.4 | 3.1% | KEV | 2023-10-10 |
| CVE-2023-36025 | Windows SmartScreen Security Feature Bypass Vulnerability | Microsoft | 8.8 | 88.1% | KEV | 2023-11-14 |
| CVE-2023-36036 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 16.7% | KEV | 2023-11-14 |
| CVE-2023-36033 | Windows DWM Core Library Elevation of Privilege Vulnerability | Microsoft | 7.8 | 10.9% | KEV | 2023-11-14 |
| CVE-2023-41763 | Skype for Business Elevation of Privilege Vulnerability | Microsoft | 5.3 | 90.4% | KEV | 2023-10-10 |
| CVE-2023-36563 | Microsoft WordPad Information Disclosure Vulnerability | Microsoft | 6.5 | 20.7% | KEV | 2023-10-10 |
| CVE-2023-28229 | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | Microsoft | 7.0 | 1.7% | KEV | 2023-04-11 |
| CVE-2023-36802 | Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability | Microsoft | 7.8 | 27.9% | KEV | 2023-09-12 |
| CVE-2023-36761 | Microsoft Word Information Disclosure Vulnerability | Microsoft | 6.5 | 19.6% | KEV | 2023-09-12 |
| CVE-2023-38180 | .NET and Visual Studio Denial of Service Vulnerability | Microsoft | 7.5 | 14.0% | KEV | 2023-08-08 |
| CVE-2023-36884 | Windows Search Remote Code Execution Vulnerability | Microsoft | 7.5 | 98.9% | KEV | 2023-07-11 |
| CVE-2023-36874 | Windows Error Reporting Service Elevation of Privilege Vulnerability | Microsoft | 7.8 | 42.6% | KEV | 2023-07-11 |
| CVE-2023-35311 | Microsoft Outlook Security Feature Bypass Vulnerability | Microsoft | 8.8 | 15.5% | KEV | 2023-07-11 |
| CVE-2023-32046 | Windows MSHTML Platform Elevation of Privilege Vulnerability | Microsoft | 7.8 | 10.0% | KEV | 2023-07-11 |
| CVE-2023-32049 | Windows SmartScreen Security Feature Bypass Vulnerability | Microsoft | 8.8 | 4.2% | KEV | 2023-07-11 |
| CVE-2016-0165 | Microsoft Win32k Privilege Escalation Vulnerability | - | 7.8 | 13.7% | KEV | 2016-04-12 |
| CVE-2023-29336 | Win32k Elevation of Privilege Vulnerability | Microsoft | 7.8 | 41.2% | KEV | 2023-05-09 |
| CVE-2023-28252 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 49.0% | KEV | 2023-04-11 |
| CVE-2019-1388 | Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability | Microsoft | 7.8 | 8.6% | KEV | 2019-11-12 |
| CVE-2013-3163 | Microsoft Internet Explorer Memory Corruption Vulnerability | - | 8.8 | 70.7% | KEV | 2013-07-10 |
| CVE-2023-23397 | Microsoft Outlook Elevation of Privilege Vulnerability | Microsoft | 9.8 | 97.2% | KEV | 2023-03-14 |
| CVE-2023-24880 | Windows SmartScreen Security Feature Bypass Vulnerability | Microsoft | 4.4 | 78.0% | KEV | 2023-03-14 |
| CVE-2023-21715 | Microsoft Publisher Security Feature Bypass Vulnerability | Microsoft | 7.3 | 12.0% | KEV | 2023-02-14 |
| CVE-2023-23376 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 10.9% | KEV | 2023-02-14 |
| CVE-2023-21823 | Windows Graphics Component Remote Code Execution Vulnerability | Microsoft | 7.8 | 5.6% | KEV | 2023-02-14 |
| CVE-2022-41080 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Microsoft | 8.8 | 77.3% | KEV | 2022-11-09 |
| CVE-2023-21674 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | Microsoft | 8.8 | 41.0% | KEV | 2023-01-10 |
| CVE-2022-44698 | Windows SmartScreen Security Feature Bypass Vulnerability | Microsoft | 5.4 | 76.3% | KEV | 2022-12-13 |
| CVE-2022-41049 | Windows Mark of the Web Security Feature Bypass Vulnerability | Microsoft | 5.4 | 2.5% | KEV | 2022-11-09 |
| CVE-2022-41128 | Windows Scripting Languages Remote Code Execution Vulnerability | Microsoft | 8.8 | 24.6% | KEV | 2022-11-09 |
| CVE-2022-41125 | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | Microsoft | 7.8 | 3.0% | KEV | 2022-11-09 |
| CVE-2022-41073 | Windows Print Spooler Elevation of Privilege Vulnerability | Microsoft | 7.8 | 2.3% | KEV | 2022-11-09 |
| CVE-2022-41091 | Windows Mark of the Web Security Feature Bypass Vulnerability | Microsoft | 5.4 | 1.8% | KEV | 2022-11-09 |
| CVE-2022-41033 | Windows COM+ Event System Service Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.9% | KEV | 2022-10-11 |
| CVE-2022-41082 | Microsoft Exchange Server Remote Code Execution Vulnerability | Microsoft | 8.0 | 100.0% | KEV | 2022-10-03 |
| CVE-2022-41040 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Microsoft | 8.8 | 100.0% | KEV | 2022-10-03 |
| CVE-2010-2568 | Microsoft Windows Remote Code Execution Vulnerability | - | 7.8 | 91.3% | KEV | 2010-07-22 |
| CVE-2022-37969 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 28.3% | KEV | 2022-09-13 |
| CVE-2022-26923 | Active Directory Domain Services Elevation of Privilege Vulnerability | Microsoft | 8.8 | 83.5% | KEV | 2022-05-10 |
| CVE-2022-21971 | Windows Runtime Remote Code Execution Vulnerability | Microsoft | 7.8 | 53.9% | KEV | 2022-02-09 |
| CVE-2022-34713 | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | Microsoft | 7.8 | 67.8% | KEV | 2022-08-09 |
| CVE-2022-22047 | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | Microsoft | 7.8 | 18.8% | KEV | 2022-07-12 |
| CVE-2022-26925 | Windows LSA Spoofing Vulnerability | Microsoft | 8.1 | 10.5% | KEV | 2022-05-10 |
| CVE-2022-30190 | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | Microsoft | 7.8 | 99.2% | KEV | 2022-06-01 |
| CVE-2012-0151 | Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability | - | 7.8 | 87.7% | KEV | 2012-04-10 |
| CVE-2012-1889 | Microsoft XML Core Services Memory Corruption Vulnerability | - | 8.8 | 83.5% | KEV | 2012-06-13 |
| CVE-2012-4969 | Microsoft Internet Explorer Use-After-Free Vulnerability | - | 8.1 | 80.3% | KEV | 2012-09-18 |
| CVE-2013-1331 | Microsoft Office Buffer Overflow Vulnerability | - | 7.8 | 79.8% | KEV | 2013-06-12 |
| CVE-2009-0563 | Microsoft Office Buffer Overflow Vulnerability | - | 7.8 | 62.8% | KEV | 2009-06-10 |
| CVE-2010-2572 | Microsoft PowerPoint Buffer Overflow Vulnerability | - | 7.8 | 58.6% | KEV | 2010-11-10 |
| CVE-2009-0557 | Microsoft Office Object Record Corruption Vulnerability | - | 7.8 | 53.0% | KEV | 2009-06-10 |
| CVE-2006-2492 | Microsoft Word Malformed Object Pointer Vulnerability | - | 8.8 | 48.1% | KEV | 2006-05-20 |
| CVE-2013-0074 | Microsoft Silverlight Double Dereference Vulnerability | - | 7.8 | 78.9% | KEV | 2013-03-13 |
| CVE-2015-0016 | Microsoft Windows TS WebProxy Directory Traversal Vulnerability | - | 7.8 | 75.8% | KEV | 2015-01-13 |
| CVE-2016-0034 | Microsoft Silverlight Runtime Remote Code Execution Vulnerability | - | 8.8 | 69.4% | KEV | 2016-01-13 |
| CVE-2016-3393 | Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability | - | 7.8 | 68.5% | KEV | 2016-10-14 |
| CVE-2013-3896 | Microsoft Silverlight Information Disclosure Vulnerability | - | 5.5 | 68.0% | KEV | 2013-10-09 |
| CVE-2016-7256 | Microsoft Windows Open Type Font Remote Code Execution Vulnerability | - | 8.8 | 64.6% | KEV | 2016-11-10 |
| CVE-2014-4148 | Microsoft Windows Remote Code Execution Vulnerability | - | 8.8 | 59.9% | KEV | 2014-10-15 |
| CVE-2014-4077 | Microsoft IME Japanese Privilege Escalation Vulnerability | - | 7.8 | 54.6% | KEV | 2014-11-11 |
| CVE-2013-7331 | Microsoft Internet Explorer Information Disclosure Vulnerability | - | 6.5 | 50.2% | KEV | 2014-02-26 |
| CVE-2015-1671 | Microsoft Windows Remote Code Execution Vulnerability | - | 7.8 | 49.0% | KEV | 2015-05-13 |
| CVE-2014-4123 | Microsoft Internet Explorer Privilege Escalation Vulnerability | - | 8.8 | 47.1% | KEV | 2014-10-15 |
| CVE-2015-2425 | Microsoft Internet Explorer Memory Corruption Vulnerability | - | 8.8 | 44.7% | KEV | 2015-07-14 |
| CVE-2015-0071 | Microsoft Internet Explorer ASLR Bypass Vulnerability | - | 6.5 | 33.6% | KEV | 2015-02-11 |
| CVE-2014-2817 | Microsoft Internet Explorer Privilege Escalation Vulnerability | - | 8.8 | 26.3% | KEV | 2014-08-12 |
| CVE-2015-2360 | Microsoft Win32k Privilege Escalation Vulnerability | - | 8.8 | 14.8% | KEV | 2015-06-10 |
| CVE-2015-6175 | Microsoft Windows Kernel Privilege Escalation Vulnerability | - | 7.8 | 5.1% | KEV | 2015-12-09 |
| CVE-2015-1769 | Microsoft Windows Mount Manager Privilege Escalation Vulnerability | - | 6.6 | 4.1% | KEV | 2015-08-15 |
| CVE-2017-0147 | Microsoft Windows SMBv1 Information Disclosure Vulnerability | Microsoft Corporation | 7.5 | 99.7% | KEV | 2017-03-17 |
| CVE-2017-8543 | Microsoft Windows Search Remote Code Execution Vulnerability | Microsoft Corporation | 9.8 | 74.2% | KEV | 2017-06-15 |
| CVE-2016-3298 | Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability | - | 6.5 | 33.3% | KEV | 2016-10-14 |
| CVE-2017-0149 | Microsoft Internet Explorer Memory Corruption Vulnerability | Microsoft Corporation | 8.8 | 29.2% | KEV | 2017-03-17 |
| CVE-2016-3351 | Microsoft Internet Explorer and Edge Information Disclosure Vulnerability | - | 6.5 | 26.5% | KEV | 2016-09-14 |
| CVE-2017-0210 | Microsoft Internet Explorer Privilege Escalation Vulnerability | Microsoft Corporation | 8.8 | 22.3% | KEV | 2017-04-12 |
| CVE-2016-0162 | Microsoft Internet Explorer Information Disclosure Vulnerability | - | 4.3 | 22.0% | KEV | 2016-04-12 |
| CVE-2017-0022 | Microsoft XML Core Services Information Disclosure Vulnerability | Microsoft Corporation | 6.5 | 18.1% | KEV | 2017-03-17 |
| CVE-2017-0005 | Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability | Microsoft Corporation | 7.8 | 11.0% | KEV | 2017-03-17 |
| CVE-2018-8611 | Microsoft Windows Kernel Privilege Escalation Vulnerability | Microsoft | 7.8 | 4.2% | KEV | 2018-12-12 |
| CVE-2019-0703 | Microsoft Windows SMB Information Disclosure Vulnerability | Microsoft | 6.5 | 9.6% | KEV | 2019-04-08 |
| CVE-2019-0676 | Microsoft Internet Explorer Information Disclosure Vulnerability | Microsoft | 6.5 | 8.1% | KEV | 2019-03-06 |
| CVE-2020-1027 | Microsoft Windows Kernel Privilege Escalation Vulnerability | Microsoft | 7.8 | 4.5% | KEV | 2020-04-15 |
| CVE-2019-1385 | Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability | Microsoft | 7.8 | 3.6% | KEV | 2019-11-12 |
| CVE-2018-8589 | Microsoft Win32k Privilege Escalation Vulnerability | Microsoft | 7.8 | 3.0% | KEV | 2018-11-14 |
| CVE-2020-0638 | Microsoft Update Notification Manager Privilege Escalation Vulnerability | Microsoft | 7.8 | 2.4% | KEV | 2020-01-14 |
| CVE-2019-0880 | Microsoft Windows Privilege Escalation Vulnerability | Microsoft | 7.8 | 2.3% | KEV | 2019-07-15 |
| CVE-2019-1130 | Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability | Microsoft | 7.8 | 1.7% | KEV | 2019-07-29 |
| CVE-2014-4113 | Microsoft Win32k Privilege Escalation Vulnerability | - | 7.8 | 86.9% | KEV | 2014-10-15 |
| CVE-2014-0322 | Microsoft Internet Explorer Use-After-Free Vulnerability | - | 8.8 | 85.1% | KEV | 2014-02-14 |
| CVE-2022-26904 | Windows User Profile Service Elevation of Privilege Vulnerability | Microsoft | 7.0 | 16.9% | KEV | 2022-04-15 |
| CVE-2022-21919 | Windows User Profile Service Elevation of Privilege Vulnerability | Microsoft | 7.0 | 2.4% | KEV | 2022-01-11 |
| CVE-2021-40450 | Win32k Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.6% | KEV | 2021-10-13 |
| CVE-2021-41357 | Win32k Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.6% | KEV | 2021-10-13 |
| CVE-2022-22718 | Windows Print Spooler Elevation of Privilege Vulnerability | Microsoft | 7.8 | 18.5% | KEV | 2022-02-09 |
| CVE-2015-2502 | Microsoft Internet Explorer Memory Corruption Vulnerability | - | 8.8 | 51.0% | KEV | 2015-08-19 |
| CVE-2022-24521 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 7.1% | KEV | 2022-04-15 |
| CVE-2021-42287 | Active Directory Domain Services Elevation of Privilege Vulnerability | Microsoft | 7.5 | 77.2% | KEV | 2021-11-10 |
| CVE-2021-42278 | Active Directory Domain Services Elevation of Privilege Vulnerability | Microsoft | 7.5 | 73.3% | KEV | 2021-11-10 |
| CVE-2021-31166 | HTTP Protocol Stack Remote Code Execution Vulnerability | Microsoft | 9.8 | 99.9% | KEV | 2021-05-11 |
| CVE-2017-0148 | Microsoft SMBv1 Server Remote Code Execution Vulnerability | Microsoft Corporation | 8.1 | 99.4% | KEV | 2017-03-17 |
| CVE-2021-34484 | Windows User Profile Service Elevation of Privilege Vulnerability | Microsoft | 7.8 | 21.8% | KEV | 2021-08-12 |
| CVE-2016-0189 | Microsoft Internet Explorer Memory Corruption Vulnerability | - | 7.5 | 94.1% | KEV | 2016-05-11 |
| CVE-2015-2426 | Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability | - | 8.8 | 86.6% | KEV | 2015-07-20 |
| CVE-2017-0213 | Microsoft Windows Privilege Escalation Vulnerability | Microsoft Corporation | 7.3 | 84.1% | KEV | 2017-05-12 |
| CVE-2016-7200 | Microsoft Edge Memory Corruption Vulnerability | - | 8.8 | 82.8% | KEV | 2016-11-10 |
| CVE-2017-0037 | Microsoft Edge and Internet Explorer Type Confusion Vulnerability | Microsoft Corporation | 8.1 | 80.4% | KEV | 2017-02-26 |
| CVE-2016-7201 | Microsoft Edge Memory Corruption Vulnerability | - | 8.8 | 80.0% | KEV | 2016-11-10 |
| CVE-2013-2551 | Microsoft Internet Explorer Use-After-Free Vulnerability | - | 8.8 | 73.9% | KEV | 2013-03-11 |
| CVE-2016-0151 | Microsoft Windows CSRSS Security Feature Bypass Vulnerability | - | 7.8 | 62.9% | KEV | 2016-04-12 |
| CVE-2017-0059 | Microsoft Internet Explorer Information Disclosure Vulnerability | Microsoft Corporation | 4.3 | 62.0% | KEV | 2017-03-17 |
| CVE-2015-2419 | Microsoft Internet Explorer Memory Corruption Vulnerability | - | 8.8 | 53.1% | KEV | 2015-07-14 |
| CVE-2012-2539 | Microsoft Word Remote Code Execution Vulnerability | - | 7.8 | 53.0% | KEV | 2012-12-12 |
| CVE-2013-3660 | Microsoft Win32k Privilege Escalation Vulnerability | - | 7.8 | 39.3% | KEV | 2013-05-24 |
| CVE-2015-1770 | Microsoft Office Uninitialized Memory Use Vulnerability | - | 8.8 | 35.0% | KEV | 2015-06-10 |
| CVE-2011-2005 | Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability | - | 7.8 | 31.8% | KEV | 2011-10-12 |
| CVE-2016-0040 | Microsoft Windows Kernel Privilege Escalation Vulnerability | - | 7.8 | 24.5% | KEV | 2016-02-10 |
| CVE-2018-8440 | Microsoft Windows Privilege Escalation Vulnerability | Microsoft | 7.8 | 18.4% | KEV | 2018-09-13 |
| CVE-2021-34486 | Windows Event Tracing Elevation of Privilege Vulnerability | Microsoft | 7.8 | 9.3% | KEV | 2021-08-12 |
| CVE-2010-4398 | Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability | - | 7.8 | 8.7% | KEV | 2010-12-03 |
| CVE-2021-38646 | Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | Microsoft | 7.8 | 8.0% | KEV | 2021-09-15 |
| CVE-2018-8405 | Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability | Microsoft | 7.8 | 3.4% | KEV | 2018-08-15 |
| CVE-2018-8406 | Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability | Microsoft | 7.8 | 3.4% | KEV | 2018-08-15 |
| CVE-2014-6332 | Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability | - | 8.8 | 94.9% | KEV | 2014-11-11 |
| CVE-2017-0146 | Microsoft Windows SMB Remote Code Execution Vulnerability | Microsoft Corporation | 8.8 | 89.9% | KEV | 2017-03-17 |
| CVE-2014-6324 | Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability | - | 8.8 | 87.3% | KEV | 2014-11-18 |
| CVE-2018-8414 | Microsoft Windows Shell Remote Code Execution Vulnerability | Microsoft | 8.8 | 72.9% | KEV | 2018-08-15 |
| CVE-2018-8373 | Microsoft Scripting Engine Memory Corruption Vulnerability | Microsoft | 7.5 | 61.9% | KEV | 2018-08-15 |
| CVE-2022-21999 | Windows Print Spooler Elevation of Privilege Vulnerability | Microsoft | 7.8 | 41.0% | KEV | 2022-02-09 |
| CVE-2019-0903 | Microsoft GDI Remote Code Execution Vulnerability | Microsoft | 8.8 | 21.7% | KEV | 2019-05-16 |
| CVE-2018-8120 | Microsoft Win32k Privilege Escalation Vulnerability | Microsoft | 7.0 | 73.4% | KEV | 2018-05-09 |
| CVE-2017-0101 | Microsoft Windows Transaction Manager Privilege Escalation Vulnerability | Microsoft Corporation | 7.8 | 57.5% | KEV | 2017-03-17 |
| CVE-2019-0841 | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability | Microsoft | 7.8 | 41.4% | KEV | 2019-04-09 |
| CVE-2019-1405 | Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability | Microsoft | 7.8 | 30.2% | KEV | 2019-11-12 |
| CVE-2016-3309 | Microsoft Windows Kernel Privilege Escalation Vulnerability | - | 7.8 | 20.5% | KEV | 2016-08-09 |
| CVE-2019-1322 | Microsoft Windows Privilege Escalation Vulnerability | Microsoft | 7.8 | 19.2% | KEV | 2019-10-10 |
| CVE-2019-1253 | Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability | Microsoft | 7.8 | 11.6% | KEV | 2019-09-11 |
| CVE-2015-2546 | Microsoft Win32k Memory Corruption Vulnerability | - | 8.2 | 10.1% | KEV | 2015-09-09 |
| CVE-2019-1132 | Microsoft Win32k Privilege Escalation Vulnerability | Microsoft | 7.8 | 9.9% | KEV | 2019-07-29 |
| CVE-2019-1064 | Windows Elevation of Privilege Vulnerability | Microsoft | 7.8 | 6.9% | KEV | 2019-06-12 |
| CVE-2019-1069 | Task Scheduler Elevation of Privilege Vulnerability | Microsoft | 7.8 | 6.1% | KEV | 2019-06-12 |
| CVE-2019-0543 | Microsoft Windows Privilege Escalation Vulnerability | - | 7.8 | 4.7% | KEV | 2019-01-08 |
| CVE-2019-1315 | Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability | Microsoft | 7.8 | 3.5% | KEV | 2019-10-10 |
| CVE-2019-1129 | Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability | Microsoft | 7.8 | 1.8% | KEV | 2019-07-29 |
| CVE-2010-3333 | Microsoft Office Stack-based Buffer Overflow Vulnerability | - | 7.8 | 89.5% | KEV | 2010-11-10 |
| CVE-2015-2545 | Microsoft Office Malformed EPS File Vulnerability | - | 7.8 | 85.9% | KEV | 2015-09-09 |
| CVE-2009-3129 | Microsoft Excel Featheader Record Memory Corruption Vulnerability | - | 7.8 | 84.0% | KEV | 2009-11-11 |
| CVE-2014-4114 | Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability | - | 7.8 | 81.6% | KEV | 2014-10-15 |
| CVE-2017-11826 | Microsoft Office Remote Code Execution Vulnerability | Microsoft Corporation | 7.8 | 81.2% | KEV | 2017-10-13 |
| CVE-2017-0261 | Microsoft Office Use-After-Free Vulnerability | Microsoft Corporation | 7.8 | 78.1% | KEV | 2017-05-12 |
| CVE-2013-1347 | Microsoft Internet Explorer Remote Code Execution Vulnerability | - | 8.8 | 77.7% | KEV | 2013-05-05 |
| CVE-2013-3897 | Microsoft Internet Explorer Use-After-Free Vulnerability | - | 8.8 | 77.3% | KEV | 2013-10-09 |
| CVE-2012-1856 | Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability | - | 8.8 | 72.0% | KEV | 2012-08-15 |
| CVE-2017-8540 | Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability | Microsoft Corporation | 7.8 | 71.9% | KEV | 2017-05-26 |
| CVE-2016-7262 | Microsoft Office Security Feature Bypass Vulnerability | - | 7.8 | 57.7% | KEV | 2016-12-20 |
| CVE-2016-7193 | Microsoft Office Memory Corruption Vulnerability | - | 7.8 | 57.6% | KEV | 2016-10-14 |
| CVE-2015-1701 | Microsoft Win32k Privilege Escalation Vulnerability | - | 7.8 | 55.9% | KEV | 2015-04-21 |
| CVE-2015-1642 | Microsoft Office Memory Corruption Vulnerability | - | 7.8 | 53.1% | KEV | 2015-08-15 |
| CVE-2011-1889 | Microsoft Forefront TMG Remote Code Execution Vulnerability | - | 9.8 | 49.0% | KEV | 2011-06-16 |
| CVE-2015-2424 | Microsoft PowerPoint Memory Corruption Vulnerability | - | 8.8 | 40.4% | KEV | 2015-07-14 |
| CVE-2016-0099 | Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability | - | 7.8 | 37.0% | KEV | 2016-03-09 |
| CVE-2015-2387 | Microsoft ATM Font Driver Privilege Escalation Vulnerability | - | 7.8 | 34.9% | KEV | 2015-07-14 |
| CVE-2013-5065 | Microsoft Windows Kernel Privilege Escalation Vulnerability | - | 7.8 | 34.7% | KEV | 2013-11-27 |
| CVE-2010-0232 | Microsoft Windows Kernel Exception Handler Vulnerability | - | 7.8 | 28.7% | KEV | 2010-01-21 |
| CVE-2018-8581 | Microsoft Exchange Server Privilege Escalation Vulnerability | Microsoft | 7.4 | 27.4% | KEV | 2018-11-14 |
| CVE-2019-1297 | Microsoft Excel Remote Code Execution Vulnerability | Microsoft | 8.8 | 21.8% | KEV | 2019-09-11 |
| CVE-2021-41379 | Windows Installer Elevation of Privilege Vulnerability | Microsoft | 5.5 | 19.5% | KEV | 2021-11-10 |
| CVE-2004-0210 | Microsoft Windows Privilege Escalation Vulnerability | - | 7.8 | 7.2% | KEV | 2004-07-14 |
| CVE-2002-0367 | Microsoft Windows Privilege Escalation Vulnerability | - | 7.8 | 4.9% | KEV | 2003-04-02 |
| CVE-2009-1123 | Microsoft Windows Improper Input Validation Vulnerability | - | 7.8 | 4.9% | KEV | 2009-06-10 |
| CVE-2017-0001 | Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability | Microsoft Corporation | 7.8 | 3.1% | KEV | 2017-03-17 |
| CVE-2017-8570 | Microsoft Office Remote Code Execution Vulnerability | Microsoft Corporation | 7.8 | 89.9% | KEV | 2017-07-11 |
| CVE-2014-6352 | Microsoft Windows Code Injection Vulnerability | - | 7.8 | 77.5% | KEV | 2014-10-22 |
| CVE-2017-0222 | Microsoft Internet Explorer Remote Code Execution Vulnerability | Microsoft Corporation | 8.8 | 29.6% | KEV | 2017-05-12 |
| CVE-2018-8174 | Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability | Microsoft | 7.5 | 88.3% | KEV | 2018-05-09 |
| CVE-2013-3906 | Microsoft Graphics Component Memory Corruption Vulnerability | - | 7.8 | 84.9% | KEV | 2013-11-06 |
| CVE-2019-0752 | Microsoft Internet Explorer Type Confusion Vulnerability | Microsoft | 7.5 | 81.7% | KEV | 2019-04-09 |
| CVE-2014-1761 | Microsoft Word Memory Corruption Vulnerability | - | 7.8 | 77.5% | KEV | 2014-03-24 |
| CVE-2015-1635 | Microsoft HTTP.sys Remote Code Execution Vulnerability | - | 9.8 | 100.0% | KEV | 2015-04-14 |
| CVE-2020-0796 | Microsoft SMBv3 Remote Code Execution Vulnerability | Microsoft | 10.0 | 99.8% | KEV | 2020-03-12 |
| CVE-2017-0144 | Microsoft SMBv1 Remote Code Execution Vulnerability | Microsoft Corporation | 8.8 | 99.2% | KEV | 2017-03-17 |
| CVE-2017-8464 | Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability | Microsoft Corporation | 8.8 | 90.0% | KEV | 2017-06-15 |
| CVE-2017-0145 | Microsoft SMBv1 Remote Code Execution Vulnerability | Microsoft Corporation | 8.8 | 89.8% | KEV | 2017-03-17 |
| CVE-2017-0262 | Microsoft Office Remote Code Execution Vulnerability | Microsoft Corporation | 7.8 | 81.0% | KEV | 2017-05-12 |
| CVE-2021-36934 | Windows Elevation of Privilege Vulnerability | Microsoft | 7.8 | 67.3% | KEV | 2021-07-22 |
| CVE-2017-0263 | Microsoft Win32k Privilege Escalation Vulnerability | Microsoft Corporation | 7.8 | 10.0% | KEV | 2017-05-12 |
| CVE-2022-21882 | Win32k Elevation of Privilege Vulnerability | Microsoft | 7.0 | 59.2% | KEV | 2022-01-11 |
| CVE-2014-1776 | Microsoft Internet Explorer Memory Corruption Vulnerability | - | 9.8 | 82.7% | KEV | 2014-04-27 |
| CVE-2020-0787 | Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability | Microsoft | 7.8 | 42.5% | KEV | 2020-03-12 |
| CVE-2018-8453 | Microsoft Win32k Privilege Escalation Vulnerability | Microsoft | 7.8 | 70.0% | KEV | 2018-10-10 |
| CVE-2021-33766 | Microsoft Exchange Server Information Disclosure Vulnerability | Microsoft | 7.3 | 98.2% | KEV | 2021-07-14 |
| CVE-2019-1458 | Microsoft Win32k Privilege Escalation Vulnerability | Microsoft | 7.8 | 74.4% | KEV | 2019-12-10 |
| CVE-2013-3900 | WinVerifyTrust Signature Validation Vulnerability | Microsoft | 5.5 | 44.6% | KEV | 2013-12-11 |
| CVE-2021-43890 | Windows AppX Installer Spoofing Vulnerability | Microsoft | 7.1 | 11.3% | KEV | 2021-12-15 |
| CVE-2021-42321 | Microsoft Exchange Server Remote Code Execution Vulnerability | Microsoft | 8.8 | 91.7% | KEV | 2021-11-10 |
| CVE-2021-40449 | Win32k Elevation of Privilege Vulnerability | Microsoft | 7.8 | 74.1% | KEV | 2021-10-13 |
| CVE-2021-42292 | Microsoft Excel Security Feature Bypass Vulnerability | Microsoft | 7.8 | 43.0% | KEV | 2021-11-10 |
| CVE-2019-0708 | Microsoft Remote Desktop Services Remote Code Execution Vulnerability | Microsoft | 9.8 | 100.0% | KEV | 2019-05-16 |
| CVE-2021-34473 | Microsoft Exchange Server Remote Code Execution Vulnerability | Microsoft | 9.1 | 100.0% | KEV | 2021-07-14 |
| CVE-2021-26855 | Microsoft Exchange Server Remote Code Execution Vulnerability | Microsoft | 9.1 | 100.0% | KEV | 2021-03-02 |
| CVE-2021-34523 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Microsoft | 9.0 | 100.0% | KEV | 2021-07-14 |
| CVE-2012-0158 | Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability | - | 8.8 | 100.0% | KEV | 2012-04-10 |
| CVE-2020-0688 | Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability | Microsoft | 8.8 | 100.0% | KEV | 2020-02-11 |
| CVE-2017-11882 | Microsoft Office Memory Corruption Vulnerability | Microsoft Corporation | 7.8 | 99.9% | KEV | 2017-11-15 |
| CVE-2021-38647 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | Microsoft | 9.8 | 99.9% | KEV | 2021-09-15 |
| CVE-2019-0604 | Microsoft SharePoint Remote Code Execution Vulnerability | Microsoft | 9.8 | 99.9% | KEV | 2019-03-06 |
| CVE-2021-27065 | Microsoft Exchange Server Remote Code Execution Vulnerability | Microsoft | 7.8 | 99.9% | KEV | 2021-03-02 |
| CVE-2017-7269 | Microsoft Windows Server Buffer Overflow Vulnerability | - | 9.8 | 99.8% | KEV | 2017-03-27 |
| CVE-2021-34527 | Windows Print Spooler Remote Code Execution Vulnerability | Microsoft | 8.8 | 99.8% | KEV | 2021-07-02 |
| CVE-2021-31207 | Microsoft Exchange Server Security Feature Bypass Vulnerability | Microsoft | 6.6 | 99.8% | KEV | 2021-05-11 |
| CVE-2017-0199 | Microsoft Office and WordPad Remote Code Execution Vulnerability | Microsoft Corporation | 7.8 | 99.5% | KEV | 2017-04-12 |
| CVE-2020-1472 | Netlogon Elevation of Privilege Vulnerability | Microsoft | 5.5 | 99.4% | KEV | 2020-08-17 |
| CVE-2020-0646 | Microsoft .NET Framework Remote Code Execution Vulnerability | Microsoft | 9.8 | 99.2% | KEV | 2020-01-14 |
| CVE-2021-40444 | Microsoft MSHTML Remote Code Execution Vulnerability | Microsoft | 8.8 | 97.5% | KEV | 2021-09-15 |
| CVE-2020-1350 | Microsoft Windows DNS Server Remote Code Execution Vulnerability | Microsoft | 10.0 | 96.7% | KEV | 2020-07-14 |
| CVE-2015-1641 | Microsoft Office Memory Corruption Vulnerability | - | 7.8 | 96.7% | KEV | 2015-04-14 |
| CVE-2021-26857 | Microsoft Exchange Server Remote Code Execution Vulnerability | Microsoft | 7.8 | 95.8% | KEV | 2021-03-02 |
| CVE-2018-0798 | Microsoft Office Memory Corruption Vulnerability | Microsoft Corporation | 8.8 | 95.1% | KEV | 2018-01-10 |
| CVE-2020-1147 | Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability | Microsoft | 7.8 | 94.0% | KEV | 2020-07-14 |
| CVE-2021-26858 | Microsoft Exchange Server Remote Code Execution Vulnerability | Microsoft | 7.8 | 93.7% | KEV | 2021-03-02 |
| CVE-2017-0143 | Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability | Microsoft Corporation | 8.8 | 93.3% | KEV | 2017-03-17 |
| CVE-2018-0802 | Microsoft Office Memory Corruption Vulnerability | Microsoft Corporation | 7.8 | 93.3% | KEV | 2018-01-10 |
| CVE-2020-0601 | Microsoft Windows CryptoAPI Spoofing Vulnerability | Microsoft | 8.1 | 89.4% | KEV | 2020-01-14 |
| CVE-2017-8759 | Microsoft .NET Framework Remote Code Execution Vulnerability | Microsoft Corporation | 7.8 | 88.7% | KEV | 2017-09-13 |
| CVE-2020-0674 | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | Microsoft | 7.5 | 86.9% | KEV | 2020-02-11 |
| CVE-2021-1675 | Windows Print Spooler Remote Code Execution Vulnerability | Microsoft | 7.8 | 85.3% | KEV | 2021-06-08 |
| CVE-2021-31955 | Windows Kernel Information Disclosure Vulnerability | Microsoft | 5.5 | 81.1% | KEV | 2021-06-08 |
| CVE-2016-7255 | Microsoft Win32k Privilege Escalation Vulnerability | - | 7.8 | 81.0% | KEV | 2016-11-10 |
| CVE-2021-26411 | Internet Explorer Memory Corruption Vulnerability | Microsoft | 8.8 | 80.8% | KEV | 2021-03-11 |
| CVE-2021-1732 | Windows Win32k Elevation of Privilege Vulnerability | Microsoft | 7.8 | 78.4% | KEV | 2021-02-25 |
| CVE-2019-1429 | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | Microsoft | 7.5 | 77.3% | KEV | 2019-11-12 |
| CVE-2016-0185 | Microsoft Windows Media Center Remote Code Execution Vulnerability | - | 7.8 | 69.8% | KEV | 2016-05-11 |
| CVE-2020-0938 | Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability | Microsoft | 7.8 | 69.0% | KEV | 2020-04-15 |
| CVE-2021-36942 | Windows LSA Spoofing Vulnerability | Microsoft | 7.5 | 66.0% | KEV | 2021-08-12 |
| CVE-2020-1020 | Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability | Microsoft | 8.8 | 65.0% | KEV | 2020-04-15 |
| CVE-2014-1812 | Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability | - | 8.8 | 64.9% | KEV | 2014-05-14 |
| CVE-2017-11774 | Microsoft Office Outlook Security Feature Bypass Vulnerability | Microsoft Corporation | 7.8 | 59.6% | KEV | 2017-10-13 |
| CVE-2021-33742 | Windows MSHTML Platform Remote Code Execution Vulnerability | Microsoft | 7.5 | 59.4% | KEV | 2021-06-08 |
| CVE-2020-1054 | Win32k Elevation of Privilege Vulnerability | Microsoft | 7.0 | 54.2% | KEV | 2020-05-21 |
| CVE-2019-0541 | Microsoft MSHTML Remote Code Execution Vulnerability | Microsoft | 8.8 | 53.2% | KEV | 2019-01-08 |
| CVE-2019-0808 | Microsoft Win32k Privilege Escalation Vulnerability | Microsoft | 7.8 | 53.0% | KEV | 2019-04-09 |
| CVE-2019-1367 | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | Microsoft | 7.5 | 52.4% | KEV | 2019-09-23 |
| CVE-2019-0803 | Microsoft Win32k Privilege Escalation Vulnerability | Microsoft | 7.8 | 45.2% | KEV | 2019-04-09 |
| CVE-2016-3235 | Microsoft Office OLE DLL Side Loading Vulnerability | - | 7.8 | 43.3% | KEV | 2016-06-16 |
| CVE-2021-34448 | Scripting Engine Memory Corruption Vulnerability | Microsoft | 6.8 | 40.1% | KEV | 2021-07-16 |
| CVE-2021-1647 | Microsoft Defender Remote Code Execution Vulnerability | Microsoft | 7.8 | 39.4% | KEV | 2021-01-12 |
| CVE-2020-1464 | Windows Spoofing Vulnerability | Microsoft | 7.8 | 38.9% | KEV | 2020-08-17 |
| CVE-2020-17144 | Microsoft Exchange Remote Code Execution Vulnerability | Microsoft | 8.4 | 36.5% | KEV | 2020-12-09 |
| CVE-2020-0968 | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | Microsoft | 7.5 | 30.7% | KEV | 2020-04-15 |
| CVE-2018-8653 | Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability | Microsoft | 7.5 | 29.6% | KEV | 2018-12-20 |
| CVE-2020-1380 | Scripting Engine Memory Corruption Vulnerability | Microsoft | 7.8 | 24.2% | KEV | 2020-08-17 |
| CVE-2021-36948 | Windows Update Medic Service Elevation of Privilege Vulnerability | Microsoft | 7.8 | 23.3% | KEV | 2021-08-12 |
| CVE-2021-31956 | Windows NTFS Elevation of Privilege Vulnerability | Microsoft | 7.8 | 22.3% | KEV | 2021-06-08 |
| CVE-2019-1215 | Microsoft Windows Privilege Escalation Vulnerability | Microsoft | 7.8 | 19.3% | KEV | 2019-09-11 |
| CVE-2020-0986 | Microsoft Windows Kernel Privilege Escalation Vulnerability | Microsoft | 7.8 | 16.4% | KEV | 2020-06-09 |
| CVE-2021-38648 | Open Management Infrastructure Elevation of Privilege Vulnerability | Microsoft | 7.8 | 11.4% | KEV | 2021-09-15 |
| CVE-2021-33771 | Windows Kernel Elevation of Privilege Vulnerability | Microsoft | 7.8 | 10.2% | KEV | 2021-07-14 |
| CVE-2021-28310 | Win32k Elevation of Privilege Vulnerability | Microsoft | 7.8 | 8.4% | KEV | 2021-04-13 |
| CVE-2020-0683 | Microsoft Windows Installer Privilege Escalation Vulnerability | Microsoft | 7.8 | 7.6% | KEV | 2020-02-11 |
| CVE-2020-1040 | Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability | Microsoft | 9.0 | 7.4% | KEV | 2020-07-14 |
| CVE-2021-33739 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Microsoft | 8.4 | 6.6% | KEV | 2021-06-08 |
| CVE-2021-27059 | Microsoft Office Remote Code Execution Vulnerability | Microsoft | 7.6 | 6.1% | KEV | 2021-03-11 |
| CVE-2016-0167 | Microsoft Win32k Privilege Escalation Vulnerability | - | 7.8 | 5.7% | KEV | 2016-04-12 |
| CVE-2021-27085 | Internet Explorer Remote Code Execution Vulnerability | Microsoft | 8.8 | 5.4% | KEV | 2021-03-11 |
| CVE-2020-17087 | Windows Kernel Local Elevation of Privilege Vulnerability | Microsoft | 7.8 | 5.4% | KEV | 2020-11-11 |
| CVE-2019-0863 | Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability | Microsoft | 7.8 | 5.2% | KEV | 2019-05-16 |
| CVE-2021-31979 | Windows Kernel Elevation of Privilege Vulnerability | Microsoft | 7.8 | 4.5% | KEV | 2021-07-14 |
| CVE-2019-0859 | Microsoft Win32k Privilege Escalation Vulnerability | Microsoft | 7.8 | 4.2% | KEV | 2019-04-09 |
| CVE-2021-36955 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 4.1% | KEV | 2021-09-15 |
| CVE-2021-31199 | Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | Microsoft | 5.2 | 3.0% | KEV | 2021-06-08 |
| CVE-2021-38649 | Open Management Infrastructure Elevation of Privilege Vulnerability | Microsoft | 7.0 | 2.9% | KEV | 2021-09-15 |
| CVE-2021-38645 | Open Management Infrastructure Elevation of Privilege Vulnerability | Microsoft | 7.8 | 2.7% | KEV | 2021-09-15 |
| CVE-2020-0878 | Microsoft Browser Memory Corruption Vulnerability | Microsoft | 4.2 | 2.7% | KEV | 2020-09-11 |
| CVE-2021-31201 | Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | Microsoft | 5.2 | 2.6% | KEV | 2021-06-08 |
| CVE-2019-0797 | Microsoft Win32k Privilege Escalation Vulnerability | Microsoft | 7.8 | 1.9% | KEV | 2019-04-09 |
| CVE-2019-1214 | Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability | Microsoft | 7.8 | 1.4% | KEV | 2019-09-11 |
| CVE-2026-20872 | NTLM Hash Disclosure Spoofing Vulnerability | Microsoft | 6.5 | 20.1% | 2026-01-13 | |
| CVE-2026-20945 | Microsoft SharePoint Server Spoofing Vulnerability | Microsoft | 4.6 | 19.1% | 2026-04-14 | |
| CVE-2026-20947 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Microsoft | 8.8 | 18.8% | 2026-01-13 | |
| CVE-2026-20925 | NTLM Hash Disclosure Spoofing Vulnerability | Microsoft | 6.5 | 18.2% | 2026-01-13 | |
| CVE-2026-21249 | Windows NTLM Spoofing Vulnerability | Microsoft | 3.3 | 11.5% | 2026-02-10 |
Frequently Asked Questions
How many Microsoft vulnerabilities are actively exploited?→
389 Microsoft CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-09-25.
Which Microsoft vulnerabilities are used in ransomware attacks?→
CISA marks 117 Microsoft KEV entries as known to be used in ransomware campaigns, including CVE-2026-45659, CVE-2026-33825, CVE-2023-21529, CVE-2025-60710, CVE-2021-43226.
Which Microsoft products have the most exploited vulnerabilities?→
- +Windows: 172 CVEs (172 in KEV)
- +Internet Explorer: 36 CVEs (36 in KEV)
- +Office: 29 CVEs (29 in KEV)
- +Win32k: 25 CVEs (25 in KEV)
- +Exchange Server: 17 CVEs (17 in KEV)
Where does Microsoft publish security advisories?→
Microsoft publishes security advisories at https://msrc.microsoft.com/update-guide. Check the vendor advisory for fixed versions and workarounds before applying updates.
Sources
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Microsoft, MITRE, CISA, or FIRST.