Skip to content
English

Products › Brands

Brand

Microsoft: actively exploited vulnerabilities

389 vulnerabilities in Microsoft products (Windows, Internet Explorer / Edge (legacy), Office…) are in CISA’s catalog of exploited vulnerabilities, 12 of them added in the last 90 days. Last added: September 25, 2026.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

By category

Add just one Microsoft category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

  • Windows 232 vulnerabilities · Operating systems
  • Internet Explorer / Edge (legacy) 44 vulnerabilities · Browsers
  • Office 43 vulnerabilities · Office and PDF
  • Exchange Server 19 vulnerabilities · Email
  • SharePoint Server 16 vulnerabilities · Collaboration and video
  • Defender 6 vulnerabilities · Security products
  • Active Directory 5 vulnerabilities · Identity and access
  • .NET / Visual Studio 4 vulnerabilities · Frameworks
  • Open Management Infrastructure (OMI) 4 vulnerabilities · Virtualization and VDI
  • Silverlight 3 vulnerabilities · Browsers
  • Outlook 2 vulnerabilities · Email
  • SQL Server 2 vulnerabilities · Business apps and data
Show 9 more products
  • AD FS 1 vulnerability · Identity and access
  • Configuration Manager 1 vulnerability · Monitoring and ITSM
  • Forefront TMG 1 vulnerability · Firewalls and VPNs
  • Hyper-V 1 vulnerability · Virtualization and VDI
  • IIS 1 vulnerability · Web servers
  • Partner Center 1 vulnerability · Virtualization and VDI
  • Power Pages 1 vulnerability · Virtualization and VDI
  • Skype for Business / Lync 1 vulnerability · Collaboration and video
  • WordPad 1 vulnerability · Office and PDF

Name used by CISA: Microsoft. Product families: indicative classification by this site.

Pace and breakdown of Microsoft vulnerabilities

The pace of newly exploited Microsoft vulnerabilities

How many Microsoft vulnerabilities join the catalog, period after period.

Number of Microsoft vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20250
Oct 4, 2025 to Nov 2, 20258
Nov 3, 2025 to Dec 2, 20251
Dec 3, 2025 to Jan 1, 20261
Jan 2, 2026 to Jan 31, 20263
Feb 1, 2026 to Mar 2, 20268
Mar 3, 2026 to Apr 1, 20261
Apr 2, 2026 to May 1, 20268
May 2, 2026 to May 31, 20267
Jun 1, 2026 to Jun 30, 20260
Jul 1, 2026 to Jul 30, 20265
Jul 31, 2026 to Aug 29, 20264
Aug 30, 2026 to Sep 28, 2026 (in progress)3

The most affected Microsoft products

The 384 Microsoft vulnerabilities in the patch list, by product family.

  • Office apps 42
  • Browser and web engines 40
  • Messaging and collaboration 36
  • Windows: kernel and drivers 32
  • Windows: services and components 16
  • Servers and virtualization 8
  • Other families (8) 33
  • Unclassified (no component given) 177

Families: this site’s taxonomy, based on the products named by Microsoft and CISA.

Priority

Patch first at Microsoft

All Microsoft vulnerabilities

In the order of the main list: recent catalog additions first, then the most severe. The number is the rank among Microsoft vulnerabilities.

  1. Rank 1Microsoft SharePoint Server

    CVE-2026-65660

    Recently addedHunt for compromise (CISA)

    Microsoft SharePoint Code Injection Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 25, 2026
    CISA deadline
    3 days
    CVSS severity
    8.8 (high)
  2. Rank 2Microsoft Windows

    CVE-2026-81963

    Recently added

    Microsoft Windows Link Following Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 8, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  3. Rank 3Microsoft Windows

    CVE-2026-85880

    Recently added

    Microsoft Windows Heap-Based Buffer Overflow Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 8, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  4. Rank 4Microsoft Windows

    CVE-2026-33824

    Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 18, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  5. Rank 5Microsoft SharePoint Server

    CVE-2026-50522

    Hunt for compromise (CISA)

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 22, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
Show the other 379 Microsoft vulnerabilities
  1. Rank 6Microsoft SharePoint Server

    CVE-2026-58644

    Hunt for compromise (CISA)

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 16, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  2. Rank 7Microsoft SharePoint Server

    CVE-2026-56164

    Hunt for compromise (CISA)

    Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 14, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  3. Rank 8Microsoft Windows

    CVE-2008-4250

    CVE from 2008, added in 2026

    Microsoft Windows Buffer Overflow Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  4. Rank 9Microsoft SharePoint Server

    CVE-2026-20963

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 18, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  5. Rank 10Microsoft Configuration Manager

    CVE-2024-43468

    CVE from 2024, added in 2026

    Microsoft Configuration Manager SQL Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 12, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  6. Rank 11Microsoft Windows

    CVE-2025-59287

    Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 24, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  7. Rank 12Microsoft SharePoint Server

    CVE-2026-55040

    Hunt for compromise (CISA)

    Microsoft SharePoint Weak Authentication Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 18, 2026
    CISA deadline
    3 days
    CVSS severity
    9.1 (critical)
  8. Rank 13Microsoft SQL Server

    CVE-2019-1068

    Hunt for compromise (CISA)CVE from 2019, added in 2026

    Microsoft SQL Server Remote Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 26, 2026
    CISA deadline
    3 days
    CVSS severity
    8.8 (high)
  9. Rank 14Microsoft SharePoint Server

    CVE-2026-45659

    Hunt for compromise (CISA)Ransomware

    Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 1, 2026
    CISA deadline
    3 days
    CVSS severity
    8.8 (high)
  10. Rank 15Microsoft Windows

    CVE-2009-1537

    CVE from 2009, added in 2026

    Microsoft DirectX NULL Byte Overwrite Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  11. Rank 16Microsoft Internet Explorer / Edge (legacy)

    CVE-2010-0249

    CVE from 2010, added in 2026

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  12. Rank 17Microsoft Internet Explorer / Edge (legacy)

    CVE-2010-0806

    CVE from 2010, added in 2026

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  13. Rank 18Microsoft Office

    CVE-2009-0238

    CVE from 2009, added in 2026

    Microsoft Office Remote Code Execution

    Added in the last 12 months: ranked by severity.

    Added
    Apr 14, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  14. Rank 19Microsoft Exchange Server

    CVE-2023-21529

    RansomwareCVE from 2023, added in 2026

    Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 13, 2026
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  15. Rank 20Microsoft Windows

    CVE-2008-0015

    CVE from 2008, added in 2026

    Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 17, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  16. Rank 21Microsoft Windows

    CVE-2026-21510

    Microsoft Windows Shell Protection Mechanism Failure Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 10, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  17. Rank 22Microsoft Windows

    CVE-2026-21513

    Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 10, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  18. Rank 23Microsoft Office

    CVE-2009-0556

    CVE from 2009, added in 2026

    Microsoft Office PowerPoint Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 7, 2026
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  19. Rank 24Microsoft Windows

    CVE-2025-33073

    Microsoft Windows SMB Client Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 20, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  20. Rank 25Microsoft Windows

    CVE-2011-3402

    CVE from 2011, added in 2025

    Microsoft Windows Remote Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 6, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  21. Rank 26Microsoft Windows

    CVE-2013-3918

    CVE from 2013, added in 2025

    Microsoft Windows Out-of-Bounds Write Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 6, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  22. Rank 27Microsoft Internet Explorer / Edge (legacy)

    CVE-2010-3962

    CVE from 2010, added in 2025

    Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 6, 2025
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  23. Rank 28Microsoft AD FS

    CVE-2026-56155

    Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 14, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  24. Rank 29Microsoft Defender

    CVE-2026-41091

    Microsoft Defender Link Following Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  25. Rank 30Microsoft Defender

    CVE-2026-33825

    Ransomware

    Microsoft Defender Insufficient Granularity of Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 22, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  26. Rank 31Microsoft Office

    CVE-2012-1854

    CVE from 2012, added in 2026

    Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 13, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  27. Rank 32Microsoft Windows

    CVE-2023-36424

    CVE from 2023, added in 2026

    Microsoft Windows Out-of-Bounds Read Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 13, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  28. Rank 33Microsoft Windows

    CVE-2025-60710

    Ransomware

    Microsoft Windows Link Following Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 13, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  29. Rank 34Microsoft Office

    CVE-2026-21514

    Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 10, 2026
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  30. Rank 35Microsoft Windows

    CVE-2026-21519

    Microsoft Windows Type Confusion Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 10, 2026
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  31. Rank 36Microsoft Windows

    CVE-2026-21533

    Microsoft Windows Improper Privilege Management Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 10, 2026
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  32. Rank 37Microsoft Office

    CVE-2026-21509

    Microsoft Office Security Feature Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 26, 2026
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  33. Rank 38Microsoft Windows

    CVE-2025-62221

    Microsoft Windows Use After Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 9, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  34. Rank 39Microsoft Windows

    CVE-2025-24990

    Microsoft Windows Untrusted Pointer Dereference Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 14, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  35. Rank 40Microsoft Windows

    CVE-2025-59230

    Microsoft Windows Improper Access Control Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 14, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  36. Rank 41Microsoft Windows

    CVE-2021-43226

    RansomwareCVE from 2021, added in 2025

    Microsoft Windows Privilege Escalation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Oct 6, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  37. Rank 42Microsoft Defender

    CVE-2026-45498

    Microsoft Defender Denial of Service Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 20, 2026
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  38. Rank 43Microsoft Windows

    CVE-2026-68820

    Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 11, 2026
    CISA deadline
    14 days
    CVSS severity
    7.0 (high)
  39. Rank 44Microsoft Windows

    CVE-2025-62215

    Microsoft Windows Race Condition Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Nov 12, 2025
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  40. Rank 45Microsoft SharePoint Server

    CVE-2026-32201

    Microsoft SharePoint Server Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 14, 2026
    CISA deadline
    14 days
    CVSS severity
    6.5 (medium)
  41. Rank 46Microsoft Windows

    CVE-2026-21525

    Microsoft Windows NULL Pointer Dereference Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 10, 2026
    CISA deadline
    21 days
    CVSS severity
    6.2 (medium)
  42. Rank 47Microsoft Exchange Server

    CVE-2026-42897

    Microsoft Exchange Server Cross-Site Scripting Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 15, 2026
    CISA deadline
    14 days
    CVSS severity
    6.1 (medium)
  43. Rank 48Microsoft Windows

    CVE-2026-20805

    Microsoft Windows Information Disclosure Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 13, 2026
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  44. Rank 49Microsoft Windows

    CVE-2026-32202

    Microsoft Windows Protection Mechanism Failure Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 28, 2026
    CISA deadline
    14 days
    CVSS severity
    4.3 (medium)
  45. Rank 50Microsoft Windows

    CVE-2020-0796

    RansomwareCVE from 2020, added in 2022

    Microsoft SMBv3 Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  46. Rank 51Microsoft Windows

    CVE-2020-1350

    Microsoft Windows DNS Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  47. Rank 52Microsoft Active Directory

    CVE-2020-1472

    Ransomware

    Microsoft Netlogon Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  48. Rank 53Microsoft SharePoint Server

    CVE-2025-53770

    Ransomware

    Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 20, 2025
    CISA deadline
    1 day
    CVSS severity
    9.8 (critical)
  49. Rank 54Microsoft Partner Center

    CVE-2024-49035

    Microsoft Partner Center Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 25, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  50. Rank 55Microsoft Power Pages

    CVE-2025-24989

    Microsoft Power Pages Improper Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 21, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  51. Rank 56Microsoft Outlook

    CVE-2024-21413

    Microsoft Outlook Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 6, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  52. Rank 57Microsoft Exchange Server

    CVE-2024-21410

    Microsoft Exchange Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  53. Rank 58Microsoft SharePoint Server

    CVE-2023-29357

    Ransomware

    Microsoft SharePoint Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  54. Rank 59Microsoft Office

    CVE-2023-23397

    Microsoft Office Outlook Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 14, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  55. Rank 60Microsoft Exchange Server

    CVE-2022-41080

    Ransomware

    Microsoft Exchange Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  56. Rank 61Microsoft Windows

    CVE-2017-8543

    CVE from 2017, added in 2022

    Microsoft Windows Search Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  57. Rank 62Microsoft Windows

    CVE-2021-31166

    Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 6, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  58. Rank 63Microsoft Forefront TMG

    CVE-2011-1889

    CVE from 2011, added in 2022

    Microsoft Forefront TMG Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  59. Rank 64Microsoft Windows

    CVE-2015-1635

    CVE from 2015, added in 2022

    Microsoft HTTP.sys Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  60. Rank 65Microsoft Internet Explorer / Edge (legacy)

    CVE-2014-1776

    CVE from 2014, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 28, 2022
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  61. Rank 66Microsoft IIS

    CVE-2017-7269

    CVE from 2017, added in 2021

    Microsoft Windows Server Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  62. Rank 67Microsoft SharePoint Server

    CVE-2019-0604

    RansomwareCVE from 2019, added in 2021

    Microsoft SharePoint Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  63. Rank 68Microsoft Windows

    CVE-2019-0708

    RansomwareCVE from 2019, added in 2021

    Microsoft Remote Desktop Services Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  64. Rank 69Microsoft .NET / Visual Studio

    CVE-2020-0646

    Microsoft .NET Framework Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  65. Rank 70Microsoft Exchange Server

    CVE-2021-26855

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  66. Rank 71Microsoft Exchange Server

    CVE-2021-34473

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  67. Rank 72Microsoft Exchange Server

    CVE-2021-34523

    Ransomware

    Microsoft Exchange Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  68. Rank 73Microsoft Open Management Infrastructure (OMI)

    CVE-2021-38647

    Ransomware

    Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  69. Rank 74Microsoft Hyper-V

    CVE-2020-1040

    Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.0 (critical)
  70. Rank 75Microsoft Office

    CVE-2007-0671

    CVE from 2007, added in 2025

    Microsoft Office Excel Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 12, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  71. Rank 76Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-3893

    CVE from 2013, added in 2025

    Microsoft Internet Explorer Resource Management Errors Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 12, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  72. Rank 77Microsoft SharePoint Server

    CVE-2025-49704

    Ransomware

    Microsoft SharePoint Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 22, 2025
    CISA deadline
    1 day
    CVSS severity
    8.8 (high)
  73. Rank 78Microsoft Windows

    CVE-2025-33053

    Microsoft Windows External Control of File Name or Path Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 10, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  74. Rank 79Microsoft Windows

    CVE-2024-49039

    Ransomware

    Microsoft Windows Task Scheduler Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 12, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  75. Rank 80Microsoft SQL Server

    CVE-2020-0618

    RansomwareCVE from 2020, added in 2024

    Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 18, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  76. Rank 81Microsoft Windows

    CVE-2024-43461

    Microsoft Windows MSHTML Platform Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 16, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  77. Rank 82Microsoft Office

    CVE-2024-38189

    Microsoft Project Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 13, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  78. Rank 83Microsoft Windows

    CVE-2018-0824

    CVE from 2018, added in 2024

    Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 5, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  79. Rank 84Microsoft Windows

    CVE-2024-30040

    Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 14, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  80. Rank 85Microsoft Windows

    CVE-2024-29988

    Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 30, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  81. Rank 86Microsoft Windows

    CVE-2023-36025

    Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 14, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  82. Rank 87Microsoft Windows

    CVE-2023-32049

    Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 11, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  83. Rank 88Microsoft Windows

    CVE-2023-21674

    Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  84. Rank 89Microsoft Windows

    CVE-2022-41128

    Microsoft Windows Scripting Languages Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 8, 2022
    CISA deadline
    31 days
    CVSS severity
    8.8 (high)
  85. Rank 90Microsoft Exchange Server

    CVE-2022-41040

    Ransomware

    Microsoft Exchange Server Server-Side Request Forgery Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 30, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  86. Rank 91Microsoft Active Directory

    CVE-2022-26923

    Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 18, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  87. Rank 92Microsoft Office

    CVE-2006-2492

    CVE from 2006, added in 2022

    Microsoft Word Malformed Object Pointer Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  88. Rank 93Microsoft Windows

    CVE-2012-1889

    CVE from 2012, added in 2022

    Microsoft XML Core Services Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  89. Rank 94Microsoft Internet Explorer / Edge (legacy)

    CVE-2014-2817

    CVE from 2014, added in 2022

    Microsoft Internet Explorer Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  90. Rank 95Microsoft Internet Explorer / Edge (legacy)

    CVE-2014-4123

    CVE from 2014, added in 2022

    Microsoft Internet Explorer Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  91. Rank 96Microsoft Windows

    CVE-2014-4148

    CVE from 2014, added in 2022

    Microsoft Windows Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  92. Rank 97Microsoft Windows

    CVE-2015-2360

    CVE from 2015, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  93. Rank 98Microsoft Internet Explorer / Edge (legacy)

    CVE-2015-2425

    CVE from 2015, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  94. Rank 99Microsoft Windows

    CVE-2016-7256

    CVE from 2016, added in 2022

    Microsoft Windows Open Type Font Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  95. Rank 100Microsoft Internet Explorer / Edge (legacy)

    CVE-2017-0149

    CVE from 2017, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  96. Rank 101Microsoft Internet Explorer / Edge (legacy)

    CVE-2017-0210

    CVE from 2017, added in 2022

    Microsoft Internet Explorer Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  97. Rank 102Microsoft Internet Explorer / Edge (legacy)

    CVE-2014-0322

    CVE from 2014, added in 2022

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 4, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  98. Rank 103Microsoft Internet Explorer / Edge (legacy)

    CVE-2015-2502

    CVE from 2015, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  99. Rank 104Microsoft Active Directory

    CVE-2021-42287

    Ransomware

    Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 11, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  100. Rank 105Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-2551

    RansomwareCVE from 2013, added in 2022

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  101. Rank 106Microsoft Office

    CVE-2015-1770

    CVE from 2015, added in 2022

    Microsoft Office Uninitialized Memory Use Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  102. Rank 107Microsoft Internet Explorer / Edge (legacy)

    CVE-2015-2419

    CVE from 2015, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  103. Rank 108Microsoft Windows

    CVE-2015-2426

    CVE from 2015, added in 2022

    Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  104. Rank 109Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-7200

    CVE from 2016, added in 2022

    Microsoft Edge Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  105. Rank 110Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-7201

    CVE from 2016, added in 2022

    Microsoft Edge Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  106. Rank 111Microsoft Active Directory

    CVE-2014-6324

    CVE from 2014, added in 2022

    Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  107. Rank 112Microsoft Windows

    CVE-2014-6332

    CVE from 2014, added in 2022

    Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  108. Rank 113Microsoft Windows

    CVE-2017-0146

    RansomwareCVE from 2017, added in 2022

    Microsoft Windows SMB Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  109. Rank 114Microsoft Windows

    CVE-2018-8414

    CVE from 2018, added in 2022

    Microsoft Windows Shell Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  110. Rank 115Microsoft Windows

    CVE-2019-0903

    CVE from 2019, added in 2022

    Microsoft GDI Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  111. Rank 116Microsoft Office

    CVE-2012-1856

    CVE from 2012, added in 2022

    Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  112. Rank 117Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-1347

    CVE from 2013, added in 2022

    Microsoft Internet Explorer Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  113. Rank 118Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-3897

    CVE from 2013, added in 2022

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  114. Rank 119Microsoft Office

    CVE-2015-2424

    CVE from 2015, added in 2022

    Microsoft PowerPoint Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  115. Rank 120Microsoft Office

    CVE-2019-1297

    CVE from 2019, added in 2022

    Microsoft Excel Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  116. Rank 121Microsoft Internet Explorer / Edge (legacy)

    CVE-2017-0222

    CVE from 2017, added in 2022

    Microsoft Internet Explorer Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 25, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  117. Rank 122Microsoft Windows

    CVE-2017-0144

    RansomwareCVE from 2017, added in 2022

    Microsoft SMBv1 Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  118. Rank 123Microsoft Windows

    CVE-2017-0145

    RansomwareCVE from 2017, added in 2022

    Microsoft SMBv1 Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  119. Rank 124Microsoft Windows

    CVE-2017-8464

    CVE from 2017, added in 2022

    Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  120. Rank 125Microsoft Windows

    CVE-2013-3900

    CVE from 2013, added in 2022

    Microsoft WinVerifyTrust function Remote Code Execution

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  121. Rank 126Microsoft Exchange Server

    CVE-2021-42321

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 17, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  122. Rank 127Microsoft Office

    CVE-2012-0158

    RansomwareCVE from 2012, added in 2021

    Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  123. Rank 128Microsoft Windows

    CVE-2014-1812

    RansomwareCVE from 2014, added in 2021

    Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  124. Rank 129Microsoft Windows

    CVE-2017-0143

    RansomwareCVE from 2017, added in 2021

    Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  125. Rank 130Microsoft Office

    CVE-2018-0798

    CVE from 2018, added in 2021

    Microsoft Office Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  126. Rank 131Microsoft Internet Explorer / Edge (legacy)

    CVE-2019-0541

    CVE from 2019, added in 2021

    Microsoft MSHTML Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  127. Rank 132Microsoft Exchange Server

    CVE-2020-0688

    Ransomware

    Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  128. Rank 133Microsoft Windows

    CVE-2020-1020

    Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  129. Rank 134Microsoft Internet Explorer / Edge (legacy)

    CVE-2020-1380

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  130. Rank 135Microsoft Exchange Server

    CVE-2020-17144

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  131. Rank 136Microsoft Internet Explorer / Edge (legacy)

    CVE-2021-26411

    Ransomware

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  132. Rank 137Microsoft Internet Explorer / Edge (legacy)

    CVE-2021-27085

    Microsoft Internet Explorer Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  133. Rank 138Microsoft Windows

    CVE-2021-33742

    Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  134. Rank 139Microsoft Windows

    CVE-2021-34448

    Microsoft Windows Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  135. Rank 140Microsoft Windows

    CVE-2021-34527

    Ransomware

    Microsoft Windows Print Spooler Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  136. Rank 141Microsoft Windows

    CVE-2023-29360

    Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 29, 2024
    CISA deadline
    21 days
    CVSS severity
    8.4 (high)
  137. Rank 142Microsoft Windows

    CVE-2015-2546

    RansomwareCVE from 2015, added in 2022

    Microsoft Win32k Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    8.2 (high)
  138. Rank 143Microsoft Windows

    CVE-2024-43573

    Microsoft Windows MSHTML Platform Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 8, 2024
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  139. Rank 144Microsoft Windows

    CVE-2024-21412

    Ransomware

    Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 13, 2024
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  140. Rank 145Microsoft Internet Explorer / Edge (legacy)

    CVE-2012-4969

    CVE from 2012, added in 2022

    Microsoft Internet Explorer Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.1 (high)
  141. Rank 146Microsoft Windows

    CVE-2017-0148

    RansomwareCVE from 2017, added in 2022

    Microsoft SMBv1 Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 6, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  142. Rank 147Microsoft Internet Explorer / Edge (legacy)

    CVE-2017-0037

    CVE from 2017, added in 2022

    Microsoft Edge and Internet Explorer Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    8.1 (high)
  143. Rank 148Microsoft Windows

    CVE-2020-0601

    Microsoft Windows CryptoAPI Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.1 (high)
  144. Rank 149Microsoft Exchange Server

    CVE-2022-41082

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 30, 2022
    CISA deadline
    21 days
    CVSS severity
    8.0 (high)
  145. Rank 150Microsoft Windows

    CVE-2025-30400

    Microsoft Windows DWM Core Library Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 13, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  146. Rank 151Microsoft Windows

    CVE-2025-32701

    Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 13, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  147. Rank 152Microsoft Windows

    CVE-2025-32706

    Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 13, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  148. Rank 153Microsoft Windows

    CVE-2025-32709

    Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 13, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  149. Rank 154Microsoft Windows

    CVE-2025-29824

    Ransomware

    Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 8, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  150. Rank 155Microsoft Windows

    CVE-2025-24985

    Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 11, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  151. Rank 156Microsoft Windows

    CVE-2025-24993

    Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 11, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  152. Rank 157Microsoft Windows

    CVE-2018-8639

    RansomwareCVE from 2018, added in 2025

    Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  153. Rank 158Microsoft Windows

    CVE-2025-21418

    Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 11, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  154. Rank 159Microsoft Windows

    CVE-2025-21333

    Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 14, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  155. Rank 160Microsoft Windows

    CVE-2025-21334

    Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 14, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  156. Rank 161Microsoft Windows

    CVE-2025-21335

    Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 14, 2025
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  157. Rank 162Microsoft Windows

    CVE-2024-35250

    Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 16, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  158. Rank 163Microsoft Windows

    CVE-2024-49138

    Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 10, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  159. Rank 164Microsoft Windows

    CVE-2024-43572

    Microsoft Windows Management Console Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 8, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  160. Rank 165Microsoft Windows

    CVE-2024-38014

    Microsoft Windows Installer Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 10, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  161. Rank 166Microsoft Windows

    CVE-2024-38107

    Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 13, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  162. Rank 167Microsoft Windows

    CVE-2024-38193

    Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 13, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  163. Rank 168Microsoft Windows

    CVE-2024-38080

    Microsoft Windows Hyper-V Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 9, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  164. Rank 169Microsoft Windows

    CVE-2024-26169

    Ransomware

    Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 13, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  165. Rank 170Microsoft Windows

    CVE-2024-30051

    Ransomware

    Microsoft DWM Core Library Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 14, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  166. Rank 171Microsoft Windows

    CVE-2022-38028

    CVE from 2022, added in 2024

    Microsoft Windows Print Spooler Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 23, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  167. Rank 172Microsoft Windows

    CVE-2024-21338

    Ransomware

    Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 4, 2024
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  168. Rank 173Microsoft Windows

    CVE-2023-36033

    Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 14, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  169. Rank 174Microsoft Windows

    CVE-2023-36036

    Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 14, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  170. Rank 175Microsoft Windows

    CVE-2023-36802

    Microsoft Streaming Service Proxy Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 12, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  171. Rank 176Microsoft Windows

    CVE-2023-32046

    Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 11, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  172. Rank 177Microsoft Windows

    CVE-2023-36874

    Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 11, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  173. Rank 178Microsoft Windows

    CVE-2016-0165

    CVE from 2016, added in 2023

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 22, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  174. Rank 179Microsoft Windows

    CVE-2023-29336

    Microsoft Win32K Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 9, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  175. Rank 180Microsoft Windows

    CVE-2023-28252

    Ransomware

    Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 11, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  176. Rank 181Microsoft Windows

    CVE-2019-1388

    RansomwareCVE from 2019, added in 2023

    Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 7, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  177. Rank 182Microsoft Windows

    CVE-2023-21823

    Microsoft Windows Graphic Component Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 14, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  178. Rank 183Microsoft Windows

    CVE-2023-23376

    Ransomware

    Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 14, 2023
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  179. Rank 184Microsoft Windows

    CVE-2022-41073

    Ransomware

    Microsoft Windows Print Spooler Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 8, 2022
    CISA deadline
    31 days
    CVSS severity
    7.8 (high)
  180. Rank 185Microsoft Windows

    CVE-2022-41125

    Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 8, 2022
    CISA deadline
    31 days
    CVSS severity
    7.8 (high)
  181. Rank 186Microsoft Windows

    CVE-2022-41033

    Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 11, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  182. Rank 187Microsoft Windows

    CVE-2010-2568

    CVE from 2010, added in 2022

    Microsoft Windows Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  183. Rank 188Microsoft Windows

    CVE-2022-37969

    Ransomware

    Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 14, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  184. Rank 189Microsoft Windows

    CVE-2022-21971

    Microsoft Windows Runtime Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 18, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  185. Rank 190Microsoft Windows

    CVE-2022-34713

    Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 9, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  186. Rank 191Microsoft Windows

    CVE-2022-22047

    Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 12, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  187. Rank 192Microsoft Windows

    CVE-2022-30190

    Ransomware

    Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 14, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  188. Rank 193Microsoft Office

    CVE-2009-0557

    CVE from 2009, added in 2022

    Microsoft Office Object Record Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  189. Rank 194Microsoft Office

    CVE-2009-0563

    CVE from 2009, added in 2022

    Microsoft Office Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  190. Rank 195Microsoft Office

    CVE-2010-2572

    CVE from 2010, added in 2022

    Microsoft PowerPoint Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  191. Rank 196Microsoft Windows

    CVE-2012-0151

    CVE from 2012, added in 2022

    Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  192. Rank 197Microsoft Office

    CVE-2013-1331

    CVE from 2013, added in 2022

    Microsoft Office Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  193. Rank 198Microsoft Windows

    CVE-2014-4077

    CVE from 2014, added in 2022

    Microsoft IME Japanese Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  194. Rank 199Microsoft Windows

    CVE-2015-0016

    CVE from 2015, added in 2022

    Microsoft Windows TS WebProxy Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  195. Rank 200Microsoft Windows

    CVE-2015-1671

    CVE from 2015, added in 2022

    Microsoft Windows Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  196. Rank 201Microsoft Windows

    CVE-2015-6175

    CVE from 2015, added in 2022

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  197. Rank 202Microsoft Windows

    CVE-2016-3393

    CVE from 2016, added in 2022

    Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  198. Rank 203Microsoft Windows

    CVE-2017-0005

    CVE from 2017, added in 2022

    Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  199. Rank 204Microsoft Windows

    CVE-2018-8611

    CVE from 2018, added in 2022

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  200. Rank 205Microsoft Windows

    CVE-2018-8589

    CVE from 2018, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  201. Rank 206Microsoft Windows

    CVE-2019-0880

    CVE from 2019, added in 2022

    Microsoft Windows Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  202. Rank 207Microsoft Windows

    CVE-2019-1130

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  203. Rank 208Microsoft Windows

    CVE-2019-1385

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  204. Rank 209Microsoft Windows

    CVE-2020-0638

    RansomwareCVE from 2020, added in 2022

    Microsoft Update Notification Manager Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  205. Rank 210Microsoft Windows

    CVE-2020-1027

    CVE from 2020, added in 2022

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  206. Rank 211Microsoft Windows

    CVE-2014-4113

    CVE from 2014, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 4, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  207. Rank 212Microsoft Windows

    CVE-2021-40450

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  208. Rank 213Microsoft Windows

    CVE-2021-41357

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  209. Rank 214Microsoft Windows

    CVE-2022-22718

    Microsoft Windows Print Spooler Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 19, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  210. Rank 215Microsoft Windows

    CVE-2022-24521

    Ransomware

    Microsoft Windows CLFS Driver Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 13, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  211. Rank 216Microsoft Windows

    CVE-2021-34484

    Microsoft Windows User Profile Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 31, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  212. Rank 217Microsoft Windows

    CVE-2010-4398

    CVE from 2010, added in 2022

    Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    24 days
    CVSS severity
    7.8 (high)
  213. Rank 218Microsoft Windows

    CVE-2011-2005

    CVE from 2011, added in 2022

    Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  214. Rank 219Microsoft Office

    CVE-2012-2539

    CVE from 2012, added in 2022

    Microsoft Word Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  215. Rank 220Microsoft Windows

    CVE-2013-3660

    CVE from 2013, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  216. Rank 221Microsoft Windows

    CVE-2016-0040

    CVE from 2016, added in 2022

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  217. Rank 222Microsoft Windows

    CVE-2016-0151

    RansomwareCVE from 2016, added in 2022

    Microsoft Windows CSRSS Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  218. Rank 223Microsoft Windows

    CVE-2018-8405

    RansomwareCVE from 2018, added in 2022

    Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  219. Rank 224Microsoft Windows

    CVE-2018-8406

    RansomwareCVE from 2018, added in 2022

    Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  220. Rank 225Microsoft Windows

    CVE-2018-8440

    RansomwareCVE from 2018, added in 2022

    Microsoft Windows Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  221. Rank 226Microsoft Windows

    CVE-2021-34486

    Microsoft Windows Event Tracing Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  222. Rank 227Microsoft Office

    CVE-2021-38646

    Ransomware

    Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  223. Rank 228Microsoft Windows

    CVE-2022-21999

    Ransomware

    Microsoft Windows Print Spooler Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  224. Rank 229Microsoft Windows

    CVE-2016-3309

    RansomwareCVE from 2016, added in 2022

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  225. Rank 230Microsoft Windows

    CVE-2017-0101

    RansomwareCVE from 2017, added in 2022

    Microsoft Windows Transaction Manager Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  226. Rank 231Microsoft Windows

    CVE-2019-0543

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  227. Rank 232Microsoft Windows

    CVE-2019-0841

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  228. Rank 233Microsoft Windows

    CVE-2019-1064

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  229. Rank 234Microsoft Windows

    CVE-2019-1069

    RansomwareCVE from 2019, added in 2022

    Microsoft Task Scheduler Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  230. Rank 235Microsoft Windows

    CVE-2019-1129

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  231. Rank 236Microsoft Windows

    CVE-2019-1132

    CVE from 2019, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  232. Rank 237Microsoft Windows

    CVE-2019-1253

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  233. Rank 238Microsoft Windows

    CVE-2019-1315

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  234. Rank 239Microsoft Windows

    CVE-2019-1322

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  235. Rank 240Microsoft Windows

    CVE-2019-1405

    RansomwareCVE from 2019, added in 2022

    Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  236. Rank 241Microsoft Windows

    CVE-2002-0367

    CVE from 2002, added in 2022

    Microsoft Windows Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  237. Rank 242Microsoft Windows

    CVE-2004-0210

    CVE from 2004, added in 2022

    Microsoft Windows Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  238. Rank 243Microsoft Windows

    CVE-2009-1123

    CVE from 2009, added in 2022

    Microsoft Windows Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  239. Rank 244Microsoft Office

    CVE-2009-3129

    CVE from 2009, added in 2022

    Microsoft Excel Featheader Record Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  240. Rank 245Microsoft Windows

    CVE-2010-0232

    CVE from 2010, added in 2022

    Microsoft Windows Kernel Exception Handler Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  241. Rank 246Microsoft Office

    CVE-2010-3333

    CVE from 2010, added in 2022

    Microsoft Office Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  242. Rank 247Microsoft Windows

    CVE-2013-5065

    CVE from 2013, added in 2022

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  243. Rank 248Microsoft Windows

    CVE-2014-4114

    CVE from 2014, added in 2022

    Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  244. Rank 249Microsoft Office

    CVE-2015-1642

    CVE from 2015, added in 2022

    Microsoft Office Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  245. Rank 250Microsoft Windows

    CVE-2015-1701

    RansomwareCVE from 2015, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  246. Rank 251Microsoft Windows

    CVE-2015-2387

    CVE from 2015, added in 2022

    Microsoft ATM Font Driver Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  247. Rank 252Microsoft Office

    CVE-2015-2545

    CVE from 2015, added in 2022

    Microsoft Office Malformed EPS File Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  248. Rank 253Microsoft Windows

    CVE-2016-0099

    RansomwareCVE from 2016, added in 2022

    Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  249. Rank 254Microsoft Office

    CVE-2016-7193

    CVE from 2016, added in 2022

    Microsoft Office Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  250. Rank 255Microsoft Office

    CVE-2016-7262

    CVE from 2016, added in 2022

    Microsoft Office Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  251. Rank 256Microsoft Windows

    CVE-2017-0001

    CVE from 2017, added in 2022

    Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  252. Rank 257Microsoft Office

    CVE-2017-0261

    CVE from 2017, added in 2022

    Microsoft Office Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  253. Rank 258Microsoft Office

    CVE-2017-11826

    CVE from 2017, added in 2022

    Microsoft Office Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  254. Rank 259Microsoft Defender

    CVE-2017-8540

    CVE from 2017, added in 2022

    Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  255. Rank 260Microsoft Windows

    CVE-2021-41379

    Ransomware

    Microsoft Windows Installer Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  256. Rank 261Microsoft Windows

    CVE-2014-6352

    CVE from 2014, added in 2022

    Microsoft Windows Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 25, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  257. Rank 262Microsoft Office

    CVE-2017-8570

    CVE from 2017, added in 2022

    Microsoft Office Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 25, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  258. Rank 263Microsoft Windows

    CVE-2013-3906

    CVE from 2013, added in 2022

    Microsoft Graphics Component Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  259. Rank 264Microsoft Office

    CVE-2014-1761

    CVE from 2014, added in 2022

    Microsoft Word Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  260. Rank 265Microsoft Office

    CVE-2017-0262

    CVE from 2017, added in 2022

    Microsoft Office Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  261. Rank 266Microsoft Windows

    CVE-2017-0263

    CVE from 2017, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  262. Rank 267Microsoft Windows

    CVE-2021-36934

    Microsoft Windows SAM Local Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 10, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  263. Rank 268Microsoft Windows

    CVE-2022-21882

    Ransomware

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 4, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  264. Rank 269Microsoft Windows

    CVE-2020-0787

    RansomwareCVE from 2020, added in 2022

    Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 28, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  265. Rank 270Microsoft Windows

    CVE-2018-8453

    RansomwareCVE from 2018, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 21, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  266. Rank 271Microsoft Windows

    CVE-2019-1458

    RansomwareCVE from 2019, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2022
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  267. Rank 272Microsoft Windows

    CVE-2021-40449

    Ransomware

    Microsoft Windows Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 17, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  268. Rank 273Microsoft Office

    CVE-2021-42292

    Microsoft Excel Security Feature Bypass

    Added more than a year ago: ranked by severity.

    Added
    Nov 17, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  269. Rank 274Microsoft Office

    CVE-2015-1641

    CVE from 2015, added in 2021

    Microsoft Office Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  270. Rank 275Microsoft Windows

    CVE-2016-0167

    RansomwareCVE from 2016, added in 2021

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  271. Rank 276Microsoft Windows

    CVE-2016-0185

    CVE from 2016, added in 2021

    Microsoft Windows Media Center Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  272. Rank 277Microsoft Office

    CVE-2016-3235

    CVE from 2016, added in 2021

    Microsoft Office OLE DLL Side Loading Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  273. Rank 278Microsoft Windows

    CVE-2016-7255

    RansomwareCVE from 2016, added in 2021

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  274. Rank 279Microsoft Office

    CVE-2017-0199

    RansomwareCVE from 2017, added in 2021

    Microsoft Office and WordPad Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  275. Rank 280Microsoft Office

    CVE-2017-11774

    CVE from 2017, added in 2021

    Microsoft Office Outlook Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  276. Rank 281Microsoft Office

    CVE-2017-11882

    RansomwareCVE from 2017, added in 2021

    Microsoft Office Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  277. Rank 282Microsoft .NET / Visual Studio

    CVE-2017-8759

    CVE from 2017, added in 2021

    Microsoft .NET Framework Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  278. Rank 283Microsoft Office

    CVE-2018-0802

    RansomwareCVE from 2018, added in 2021

    Microsoft Office Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  279. Rank 284Microsoft Windows

    CVE-2019-0797

    CVE from 2019, added in 2021

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  280. Rank 285Microsoft Windows

    CVE-2019-0803

    RansomwareCVE from 2019, added in 2021

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  281. Rank 286Microsoft Windows

    CVE-2019-0808

    CVE from 2019, added in 2021

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  282. Rank 287Microsoft Windows

    CVE-2019-0859

    RansomwareCVE from 2019, added in 2021

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  283. Rank 288Microsoft Windows

    CVE-2019-0863

    CVE from 2019, added in 2021

    Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  284. Rank 289Microsoft Windows

    CVE-2019-1214

    CVE from 2019, added in 2021

    Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  285. Rank 290Microsoft Windows

    CVE-2019-1215

    RansomwareCVE from 2019, added in 2021

    Microsoft Windows Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  286. Rank 291Microsoft Windows

    CVE-2020-0683

    Microsoft Windows Installer Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  287. Rank 292Microsoft Windows

    CVE-2020-0938

    Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  288. Rank 293Microsoft Windows

    CVE-2020-0986

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  289. Rank 294Microsoft Windows

    CVE-2020-1054

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  290. Rank 295Microsoft SharePoint Server

    CVE-2020-1147

    Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  291. Rank 296Microsoft Windows

    CVE-2020-17087

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  292. Rank 297Microsoft Defender

    CVE-2021-1647

    Microsoft Defender Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  293. Rank 298Microsoft Windows

    CVE-2021-1675

    Ransomware

    Microsoft Windows Print Spooler Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  294. Rank 299Microsoft Windows

    CVE-2021-1732

    Ransomware

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  295. Rank 300Microsoft Exchange Server

    CVE-2021-26857

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  296. Rank 301Microsoft Exchange Server

    CVE-2021-26858

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  297. Rank 302Microsoft Exchange Server

    CVE-2021-27065

    Ransomware

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.8 (high)
  298. Rank 303Microsoft Windows

    CVE-2021-28310

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  299. Rank 304Microsoft Windows

    CVE-2021-31199

    Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  300. Rank 305Microsoft Windows

    CVE-2021-31201

    Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  301. Rank 306Microsoft Windows

    CVE-2021-31956

    Microsoft Windows NTFS Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  302. Rank 307Microsoft Windows

    CVE-2021-31979

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  303. Rank 308Microsoft Windows

    CVE-2021-33739

    Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  304. Rank 309Microsoft Windows

    CVE-2021-33771

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  305. Rank 310Microsoft Windows

    CVE-2021-36948

    Microsoft Windows Update Medic Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  306. Rank 311Microsoft Windows

    CVE-2021-36955

    Ransomware

    Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  307. Rank 312Microsoft Open Management Infrastructure (OMI)

    CVE-2021-38645

    Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  308. Rank 313Microsoft Open Management Infrastructure (OMI)

    CVE-2021-38648

    Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  309. Rank 314Microsoft Open Management Infrastructure (OMI)

    CVE-2021-38649

    Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  310. Rank 315Microsoft Internet Explorer / Edge (legacy)

    CVE-2021-40444

    Ransomware

    Microsoft MSHTML Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  311. Rank 316Microsoft Windows

    CVE-2024-21351

    Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 13, 2024
    CISA deadline
    21 days
    CVSS severity
    7.6 (high)
  312. Rank 317Microsoft Windows

    CVE-2025-30397

    Microsoft Windows Scripting Engine Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 13, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  313. Rank 318Microsoft .NET / Visual Studio

    CVE-2024-29059

    Microsoft .NET Framework Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 4, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  314. Rank 319Microsoft Windows

    CVE-2024-38178

    Microsoft Windows Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 13, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  315. Rank 320Microsoft Windows

    CVE-2024-38112

    Microsoft Windows MSHTML Platform Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 9, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  316. Rank 321Microsoft .NET / Visual Studio

    CVE-2023-38180

    Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 9, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  317. Rank 322Microsoft Windows

    CVE-2023-36884

    Ransomware

    Microsoft Windows Search Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 17, 2023
    CISA deadline
    43 days
    CVSS severity
    7.5 (high)
  318. Rank 323Microsoft Outlook

    CVE-2023-35311

    Microsoft Outlook Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 11, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  319. Rank 324Microsoft Windows

    CVE-2017-0147

    RansomwareCVE from 2017, added in 2022

    Microsoft Windows SMBv1 Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  320. Rank 325Microsoft Active Directory

    CVE-2021-42278

    Ransomware

    Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 11, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  321. Rank 326Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-0189

    RansomwareCVE from 2016, added in 2022

    Microsoft Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  322. Rank 327Microsoft Internet Explorer / Edge (legacy)

    CVE-2018-8373

    CVE from 2018, added in 2022

    Microsoft Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  323. Rank 328Microsoft Windows

    CVE-2018-8174

    RansomwareCVE from 2018, added in 2022

    Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  324. Rank 329Microsoft Internet Explorer / Edge (legacy)

    CVE-2019-0752

    RansomwareCVE from 2019, added in 2022

    Microsoft Internet Explorer Type Confusion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2022
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  325. Rank 330Microsoft Exchange Server

    CVE-2021-33766

    Microsoft Exchange Server Information Disclosure

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2022
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  326. Rank 331Microsoft Internet Explorer / Edge (legacy)

    CVE-2018-8653

    CVE from 2018, added in 2021

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  327. Rank 332Microsoft Internet Explorer / Edge (legacy)

    CVE-2019-1367

    RansomwareCVE from 2019, added in 2021

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  328. Rank 333Microsoft Internet Explorer / Edge (legacy)

    CVE-2019-1429

    CVE from 2019, added in 2021

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  329. Rank 334Microsoft Internet Explorer / Edge (legacy)

    CVE-2020-0674

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  330. Rank 335Microsoft Internet Explorer / Edge (legacy)

    CVE-2020-0878

    Ransomware

    Microsoft Edge and Internet Explorer Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  331. Rank 336Microsoft Internet Explorer / Edge (legacy)

    CVE-2020-0968

    Ransomware

    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  332. Rank 337Microsoft Windows

    CVE-2021-36942

    Ransomware

    Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  333. Rank 338Microsoft Exchange Server

    CVE-2018-8581

    RansomwareCVE from 2018, added in 2022

    Microsoft Exchange Server Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.4 (high)
  334. Rank 339Microsoft Office

    CVE-2024-38226

    Microsoft Publisher Protection Mechanism Failure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 10, 2024
    CISA deadline
    21 days
    CVSS severity
    7.3 (high)
  335. Rank 340Microsoft Office

    CVE-2023-21715

    Microsoft Office Publisher Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 14, 2023
    CISA deadline
    21 days
    CVSS severity
    7.3 (high)
  336. Rank 341Microsoft Windows

    CVE-2017-0213

    RansomwareCVE from 2017, added in 2022

    Microsoft Windows Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    7.3 (high)
  337. Rank 342Microsoft SharePoint Server

    CVE-2024-38094

    Ransomware

    Microsoft SharePoint Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 22, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  338. Rank 343Microsoft Exchange Server

    CVE-2021-31196

    CVE from 2021, added in 2024

    Microsoft Exchange Server Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 21, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  339. Rank 344Microsoft SharePoint Server

    CVE-2023-24955

    Ransomware

    Microsoft SharePoint Server Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 26, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  340. Rank 345Microsoft Windows

    CVE-2025-21391

    Microsoft Windows Storage Link Following Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 11, 2025
    CISA deadline
    21 days
    CVSS severity
    7.1 (high)
  341. Rank 346Microsoft Windows

    CVE-2021-43890

    Ransomware

    Microsoft Windows AppX Installer Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 15, 2021
    CISA deadline
    14 days
    CVSS severity
    7.1 (high)
  342. Rank 347Microsoft Windows

    CVE-2025-24983

    Microsoft Windows Win32k Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 11, 2025
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  343. Rank 348Microsoft Windows

    CVE-2025-26633

    Ransomware

    Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 11, 2025
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  344. Rank 349Microsoft Windows

    CVE-2024-30088

    Ransomware

    Microsoft Windows Kernel TOCTOU Race Condition Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 15, 2024
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  345. Rank 350Microsoft Windows

    CVE-2024-38106

    Microsoft Windows Kernel Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 13, 2024
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  346. Rank 351Microsoft Windows

    CVE-2023-28229

    Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 4, 2023
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  347. Rank 352Microsoft Windows

    CVE-2022-21919

    Microsoft Windows User Profile Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  348. Rank 353Microsoft Windows

    CVE-2022-26904

    Microsoft Windows User Profile Service Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  349. Rank 354Microsoft Windows

    CVE-2018-8120

    RansomwareCVE from 2018, added in 2022

    Microsoft Win32k Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 15, 2022
    CISA deadline
    21 days
    CVSS severity
    7.0 (high)
  350. Rank 355Microsoft Windows

    CVE-2015-1769

    CVE from 2015, added in 2022

    Microsoft Windows Mount Manager Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    6.6 (medium)
  351. Rank 356Microsoft Exchange Server

    CVE-2021-31207

    Ransomware

    Microsoft Exchange Server Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    6.6 (medium)
  352. Rank 357Microsoft SharePoint Server

    CVE-2025-49706

    Ransomware

    Microsoft SharePoint Improper Authentication Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 22, 2025
    CISA deadline
    1 day
    CVSS severity
    6.5 (medium)
  353. Rank 358Microsoft Windows

    CVE-2024-43451

    Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 12, 2024
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  354. Rank 359Microsoft Windows

    CVE-2024-38213

    Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 13, 2024
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  355. Rank 360Microsoft Office

    CVE-2023-36761

    Microsoft Word Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 12, 2023
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  356. Rank 361Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-7331

    CVE from 2013, added in 2022

    Microsoft Internet Explorer Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  357. Rank 362Microsoft Internet Explorer / Edge (legacy)

    CVE-2015-0071

    CVE from 2015, added in 2022

    Microsoft Internet Explorer ASLR Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  358. Rank 363Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-3298

    CVE from 2016, added in 2022

    Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  359. Rank 364Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-3351

    RansomwareCVE from 2016, added in 2022

    Microsoft Internet Explorer and Edge Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  360. Rank 365Microsoft Windows

    CVE-2017-0022

    CVE from 2017, added in 2022

    Microsoft XML Core Services Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  361. Rank 366Microsoft Internet Explorer / Edge (legacy)

    CVE-2019-0676

    CVE from 2019, added in 2022

    Microsoft Internet Explorer Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  362. Rank 367Microsoft Windows

    CVE-2019-0703

    CVE from 2019, added in 2022

    Microsoft Windows SMB Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  363. Rank 368Microsoft Office

    CVE-2021-27059

    Microsoft Office Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    6.5 (medium)
  364. Rank 369Microsoft Windows

    CVE-2022-26925

    Microsoft Windows LSA Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 1, 2022
    CISA deadline
    21 days
    CVSS severity
    5.9 (medium)
  365. Rank 370Microsoft Windows

    CVE-2025-24991

    Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 11, 2025
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  366. Rank 371Microsoft WordPad

    CVE-2023-36563

    Microsoft WordPad Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 10, 2023
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  367. Rank 372Microsoft Windows

    CVE-2020-1464

    Microsoft Windows Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    5.5 (medium)
  368. Rank 373Microsoft Windows

    CVE-2021-31955

    Microsoft Windows Kernel Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    5.5 (medium)
  369. Rank 374Microsoft Windows

    CVE-2025-24054

    Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 17, 2025
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  370. Rank 375Microsoft Windows

    CVE-2024-38217

    Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 10, 2024
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  371. Rank 376Microsoft Windows

    CVE-2023-36584

    Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 16, 2023
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  372. Rank 377Microsoft Defender

    CVE-2022-44698

    Ransomware

    Microsoft Defender SmartScreen Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Dec 13, 2022
    CISA deadline
    21 days
    CVSS severity
    5.4 (medium)
  373. Rank 378Microsoft Windows

    CVE-2022-41049

    Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 14, 2022
    CISA deadline
    25 days
    CVSS severity
    5.4 (medium)
  374. Rank 379Microsoft Windows

    CVE-2022-41091

    Ransomware

    Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 8, 2022
    CISA deadline
    31 days
    CVSS severity
    5.4 (medium)
  375. Rank 380Microsoft Skype for Business / Lync

    CVE-2023-41763

    Microsoft Skype for Business Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 10, 2023
    CISA deadline
    21 days
    CVSS severity
    5.3 (medium)
  376. Rank 381Microsoft Windows

    CVE-2025-24984

    Microsoft Windows NTFS Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 11, 2025
    CISA deadline
    21 days
    CVSS severity
    4.6 (medium)
  377. Rank 382Microsoft Windows

    CVE-2023-24880

    Ransomware

    Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 14, 2023
    CISA deadline
    21 days
    CVSS severity
    4.4 (medium)
  378. Rank 383Microsoft Internet Explorer / Edge (legacy)

    CVE-2016-0162

    CVE from 2016, added in 2022

    Microsoft Internet Explorer Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    4.3 (medium)
  379. Rank 384Microsoft Internet Explorer / Edge (legacy)

    CVE-2017-0059

    CVE from 2017, added in 2022

    Microsoft Internet Explorer Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 28, 2022
    CISA deadline
    21 days
    CVSS severity
    4.3 (medium)

End of life: remove

These Microsoft products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. Microsoft Internet Explorer / Edge (legacy)

    CVE-2012-4792

    End of lifeCVE from 2012, added in 2024

    Microsoft Internet Explorer Use-After-Free Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Jul 23, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  2. Microsoft Internet Explorer / Edge (legacy)

    CVE-2013-3163

    End of lifeCVE from 2013, added in 2023

    Microsoft Internet Explorer Memory Corruption Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Mar 30, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  3. Microsoft Silverlight

    CVE-2013-0074

    RansomwareEnd of lifeCVE from 2013, added in 2022

    Microsoft Silverlight Double Dereference Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  4. Microsoft Silverlight

    CVE-2013-3896

    End of lifeCVE from 2013, added in 2022

    Microsoft Silverlight Information Disclosure Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    5.5 (medium)
  5. Microsoft Silverlight

    CVE-2016-0034

    RansomwareEnd of lifeCVE from 2016, added in 2022

    Microsoft Silverlight Runtime Remote Code Execution Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    May 25, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)

Going further: Patch Tuesday and identity

Identity vulnerabilities

6 vulnerabilities in the list affect identity (Active Directory, Kerberos, Entra ID…): this kind of flaw often hands over the whole network.

See them in the patch list

Patch Tuesday

Microsoft releases its security updates every month on the second Tuesday (“Patch Tuesday”), and sometimes out of band. The page of each Microsoft vulnerability shows the patch date and the monthly release when Microsoft publishes them, with a link to the vulnerability’s page in its Security Update Guide.

Microsoft Edge and Chromium

Microsoft Edge is built on Chromium: Chromium (Google) vulnerabilities affect it too. See Google vulnerabilities (Chrome, Chromium).

Follow and verify

Get new Microsoft vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.