Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,234

Total CVEs

1,589

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1599
MEDIUM 7
INFO 620

Showing 20 of 536 CVEs matching "Microsoft"

CVE-2025-24985KEV
High

Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.

MicrosoftEPSS 1.1%
CVE-2025-24983KEV
High

Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

MicrosoftEPSS 0.7%
CVE-2025-24991KEV
High

Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.

MicrosoftEPSS 0.7%
CVE-2025-24993KEV
High

Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.

MicrosoftEPSS 1.5%
CVE-2025-26633KEV
High

Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.

MicrosoftEPSS 7.1%
CVE-2018-8639KEV
High

Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

MicrosoftEPSS 31.9%
CVE-2024-49035KEV
High

Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges.

MicrosoftEPSS 6.2%
CVE-2025-24989KEV
High

Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.

MicrosoftEPSS 25.7%
CVE-2025-21391KEV
High

Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.

MicrosoftEPSS 2.5%
CVE-2025-21418KEV
High

Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.

MicrosoftEPSS 9.5%
CVE-2025-0994KEV
High

Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server.

TrimbleEPSS 77.8%
CVE-2024-21413KEV
High

Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.

MicrosoftEPSS 93.3%
CVE-2024-29059KEV
High

Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.

MicrosoftEPSS 93.8%
CVE-2025-21335KEV
High

Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.

MicrosoftEPSS 8.7%
CVE-2025-21333KEV
High

Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.

MicrosoftEPSS 80.7%
CVE-2025-21334KEV
High

Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.

MicrosoftEPSS 6.6%
CVE-2024-35250KEV
High

Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges.

MicrosoftEPSS 53.7%
CVE-2024-49138KEV
High

Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges.

MicrosoftEPSS 84.5%
CVE-2024-49039KEV
High

Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions.

MicrosoftEPSS 65.9%
CVE-2024-43451KEV
High

Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user.

MicrosoftEPSS 90.3%