Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2025-49706 | Microsoft | SharePoint | Microsoft SharePoint Improper Authentication Vulnerability Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706. | 6.5 CNA | 2025-07-22 | 2025-07-23 | Known |
| CVE-2025-49704 | Microsoft | SharePoint | Microsoft SharePoint Code Injection Vulnerability Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704. | 8.8 CNA | 2025-07-22 | 2025-07-23 | Known |
| CVE-2025-53770 | Microsoft | SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704. | 9.8 CNA | 2025-07-20 | 2025-07-21 | Known |
| CVE-2025-33053 | Microsoft | Windows | Microsoft Windows External Control of File Name or Path Vulnerability Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribute of Internet Shortcut files. | 8.8 CNA | 2025-06-10 | 2025-07-01 | Unknown |
| CVE-2025-30400 | Microsoft | Windows | Microsoft Windows DWM Core Library Use-After-Free Vulnerability Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. | 7.8 CNA | 2025-05-13 | 2025-06-03 | Unknown |
| CVE-2025-32701 | Microsoft | Windows | Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. | 7.8 CNA | 2025-05-13 | 2025-06-03 | Unknown |
| CVE-2025-32706 | Microsoft | Windows | Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally. | 7.8 CNA | 2025-05-13 | 2025-06-03 | Unknown |
| CVE-2025-30397 | Microsoft | Windows | Microsoft Windows Scripting Engine Type Confusion Vulnerability Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL. | 7.5 CNA | 2025-05-13 | 2025-06-03 | Unknown |
| CVE-2025-32709 | Microsoft | Windows | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privileges to administrator. | 7.8 CNA | 2025-05-13 | 2025-06-03 | Unknown |
| CVE-2025-24054 | Microsoft | Windows | Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network. | 6.5 CNA | 2025-04-17 | 2025-05-08 | Unknown |
| CVE-2025-29824 | Microsoft | Windows | Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. | 7.8 CNA | 2025-04-08 | 2025-04-29 | Known |
| CVE-2025-26633 | Microsoft | Windows | Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally. | 7.0 CNA | 2025-03-11 | 2025-04-01 | Known |
| CVE-2025-24983 | Microsoft | Windows | Microsoft Windows Win32k Use-After-Free Vulnerability Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. | 7.0 CNA | 2025-03-11 | 2025-04-01 | Unknown |
| CVE-2025-24984 | Microsoft | Windows | Microsoft Windows NTFS Information Disclosure Vulnerability Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory. | 4.6 CNA | 2025-03-11 | 2025-04-01 | Unknown |
| CVE-2025-24985 | Microsoft | Windows | Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally. | 7.8 CNA | 2025-03-11 | 2025-04-01 | Unknown |
| CVE-2025-24991 | Microsoft | Windows | Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally. | 5.5 CNA | 2025-03-11 | 2025-04-01 | Unknown |
| CVE-2025-24993 | Microsoft | Windows | Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally. | 7.8 CNA | 2025-03-11 | 2025-04-01 | Unknown |
| CVE-2018-8639 | Microsoft | Windows | Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. | 8.4 CISA | 2025-03-03 | 2025-03-24 | Known |
| CVE-2024-49035 | Microsoft | Partner Center | Microsoft Partner Center Improper Access Control Vulnerability Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges. | 8.7 CNA | 2025-02-25 | 2025-03-18 | Unknown |
| CVE-2025-24989 | Microsoft | Power Pages | Microsoft Power Pages Improper Access Control Vulnerability Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. | 8.2 CNA | 2025-02-21 | 2025-03-14 | Unknown |
| CVE-2025-21391 | Microsoft | Windows | Microsoft Windows Storage Link Following Vulnerability Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable. | 7.1 CNA | 2025-02-11 | 2025-03-04 | Unknown |
| CVE-2025-21418 | Microsoft | Windows | Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. | 7.8 CNA | 2025-02-11 | 2025-03-04 | Unknown |
| CVE-2024-21413 | Microsoft | Office Outlook | Microsoft Outlook Improper Input Validation Vulnerability Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode. | 9.8 CNA | 2025-02-06 | 2025-02-27 | Unknown |
| CVE-2024-29059 | Microsoft | .NET Framework | Microsoft .NET Framework Information Disclosure Vulnerability Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution. | 7.5 CNA | 2025-02-04 | 2025-02-25 | Unknown |
| CVE-2025-21333 | Microsoft | Windows | Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges. | 7.8 CNA | 2025-01-14 | 2025-02-04 | Unknown |
| CVE-2025-21334 | Microsoft | Windows | Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges. | 7.8 CNA | 2025-01-14 | 2025-02-04 | Unknown |
| CVE-2025-21335 | Microsoft | Windows | Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges. | 7.8 CNA | 2025-01-14 | 2025-02-04 | Unknown |
| CVE-2024-35250 | Microsoft | Windows | Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges. | 7.8 CNA | 2024-12-16 | 2025-01-06 | Unknown |
| CVE-2024-49138 | Microsoft | Windows | Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges. | 7.8 CNA | 2024-12-10 | 2024-12-31 | Unknown |
| CVE-2024-49039 | Microsoft | Windows | Microsoft Windows Task Scheduler Privilege Escalation Vulnerability Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions. | 8.8 CNA | 2024-11-12 | 2024-12-03 | Known |
| CVE-2024-43451 | Microsoft | Windows | Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user. | 6.5 CNA | 2024-11-12 | 2024-12-03 | Unknown |
| CVE-2024-38094 | Microsoft | SharePoint | Microsoft SharePoint Deserialization Vulnerability Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution. | 7.2 CNA | 2024-10-22 | 2024-11-12 | Known |
| CVE-2024-30088 | Microsoft | Windows | Microsoft Windows Kernel TOCTOU Race Condition Vulnerability Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation. | 7.0 CNA | 2024-10-15 | 2024-11-05 | Known |
| CVE-2024-43572 | Microsoft | Windows | Microsoft Windows Management Console Remote Code Execution Vulnerability Microsoft Windows Management Console contains unspecified vulnerability that allows for remote code execution. | 7.8 CNA | 2024-10-08 | 2024-10-29 | Unknown |
| CVE-2024-43573 | Microsoft | Windows | Microsoft Windows MSHTML Platform Spoofing Vulnerability Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can lead to a loss of confidentiality. | 6.5 CNA | 2024-10-08 | 2024-10-29 | Unknown |
| CVE-2020-0618 | Microsoft | SQL Server | Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account. | 9.8 CISA | 2024-09-18 | 2024-10-09 | Known |
| CVE-2024-43461 | Microsoft | Windows | Microsoft Windows MSHTML Platform Spoofing Vulnerability Microsoft Windows MSHTML Platform contains a user interface (UI) misrepresentation of critical information vulnerability that allows an attacker to spoof a web page. This vulnerability was exploited in conjunction with CVE-2024-38112. | 8.8 CNA | 2024-09-16 | 2024-10-07 | Unknown |
| CVE-2024-38226 | Microsoft | Publisher | Microsoft Publisher Protection Mechanism Failure Vulnerability Microsoft Publisher contains a protection mechanism failure vulnerability that allows attacker to bypass Office macro policies used to block untrusted or malicious files. | 7.3 CNA | 2024-09-10 | 2024-10-01 | Unknown |
| CVE-2024-38014 | Microsoft | Windows | Microsoft Windows Installer Improper Privilege Management Vulnerability Microsoft Windows Installer contains an improper privilege management vulnerability that could allow an attacker to gain SYSTEM privileges. | 7.8 CNA | 2024-09-10 | 2024-10-01 | Unknown |
| CVE-2024-38217 | Microsoft | Windows | Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging. | 5.4 CNA | 2024-09-10 | 2024-10-01 | Unknown |
| CVE-2021-31196 | Microsoft | Exchange Server | Microsoft Exchange Server Information Disclosure Vulnerability Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution. | 7.2 CNA | 2024-08-21 | 2024-09-11 | Unknown |
| CVE-2024-38189 | Microsoft | Project | Microsoft Project Remote Code Execution Vulnerability Microsoft Project contains an unspecified vulnerability that allows for remote code execution via a malicious file. | 8.8 CNA | 2024-08-13 | 2024-09-03 | Unknown |
| CVE-2024-38178 | Microsoft | Windows | Microsoft Windows Scripting Engine Memory Corruption Vulnerability Microsoft Windows Scripting Engine contains a memory corruption vulnerability that allows unauthenticated attacker to initiate remote code execution via a specially crafted URL. | 7.5 CNA | 2024-08-13 | 2024-09-03 | Unknown |
| CVE-2024-38213 | Microsoft | Windows | Microsoft Windows SmartScreen Security Feature Bypass Vulnerability Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file. | 6.5 CNA | 2024-08-13 | 2024-09-03 | Unknown |
| CVE-2024-38193 | Microsoft | Windows | Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. | 7.8 CNA | 2024-08-13 | 2024-09-03 | Unknown |
| CVE-2024-38106 | Microsoft | Windows | Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Successful exploitation of this vulnerability requires an attacker to win a race condition. | 7.0 CNA | 2024-08-13 | 2024-09-03 | Unknown |
| CVE-2024-38107 | Microsoft | Windows | Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability Microsoft Windows Power Dependency Coordinator contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to obtain SYSTEM privileges. | 7.8 CNA | 2024-08-13 | 2024-09-03 | Unknown |
| CVE-2018-0824 | Microsoft | Windows | Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script. | 7.5 CISA | 2024-08-05 | 2024-08-26 | Unknown |
| CVE-2012-4792 | Microsoft | Internet Explorer | Microsoft Internet Explorer Use-After-Free Vulnerability Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object. | 8.8 CISA | 2024-07-23 | 2024-08-13 | Unknown |
| CVE-2024-38112 | Microsoft | Windows | Microsoft Windows MSHTML Platform Spoofing Vulnerability Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability. | 7.5 CNA | 2024-07-09 | 2024-07-30 | Unknown |