Most Exploited Internet-Facing Products

MEIFP

Back to Ranking

Microsoft

Products: .NET · ASP.NET Core · Azure Kubernetes Service · Azure Migrate · Microsoft .NET Framework · Microsoft 365 Apps for Enterprise · Microsoft Azure Functions · Microsoft Configuration Manager · Microsoft Dataverse · Microsoft Defender for IoT · Microsoft Edge (Chromium-based) · Microsoft Entra · Microsoft Exchange Server 2016 Cumulative Update 23 · Microsoft Exchange Server 2019 Cumulative Update 13 · Microsoft Exchange Server 2019 Cumulative Update 14 · Microsoft Exchange Server 2019 Cumulative Update 15 · Microsoft Exchange Server Subscription Edition RTM · Microsoft ODBC Driver 17 for SQL Server on Linux · Microsoft ODBC Driver 17 for SQL Server on MacOS · Microsoft ODBC Driver 17 for SQL Server on Windows

544.8

Score

39

CVEs

15

Active

24

PoC

15

KEV

#3

Rank

Period:
Product:
CVE IDCVSSExploitScore(hover)Affected Products
CVE-2026-493365.5v4.0POC
0.0
kiota-typescript
CVE-2026-464028.1v3.1POC
0.0
UFO
CVE-2026-464148.8v3.1POC
0.0
UFO
CVE-2026-464166.3v3.1POC
0.0
UFO
CVE-2026-465445.3v3.1POC
0.0
UFO
CVE-2026-322016.5v3.1ACTIVE
40.6
Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019Microsoft SharePoint Server Subscription Edition
CVE-2026-248886.5v3.1POC
0.0
maker.js
CVE-2026-209639.8v3.1ACTIVE
40.6
Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019Microsoft SharePoint Server Subscription Edition
CVE-2025-553159.9v3.1POC
0.0
ASP.NET CoreMicrosoft Visual Studio 2022 version 17.10Microsoft Visual Studio 2022 version 17.12Microsoft Visual Studio 2022 version 17.14
CVE-2025-592879.8v3.1ACTIVE
40.6
Windows Server 2012Windows Server 2012 (Server Core installation)Windows Server 2012 R2Windows Server 2012 R2 (Server Core installation)Windows Server 2016Windows Server 2016 (Server Core installation)Windows Server 2019Windows Server 2019 (Server Core installation)Windows Server 2022Windows Server 2022, 23H2 Edition (Server Core installation)
CVE-2025-5491410.0v3.1POC
0.0
Networking
CVE-2025-5524110.0v3.1POC
0.0
Microsoft Entra
CVE-2025-501659.8v3.1POC
0.0
Windows 11 Version 24H2Windows Server 2025Windows Server 2025 (Server Core installation)
CVE-2025-537709.8v3.1ACTIVE
40.6
Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019Microsoft SharePoint Server Subscription Edition
CVE-2025-497048.8v3.1ACTIVE
26.4
Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019
CVE-2025-497066.5v3.1ACTIVE
31.2
Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019Microsoft SharePoint Server Subscription Edition
CVE-2025-73267.0v3.1POC
0.0
ASP.NET CoreMicrosoft.AspNetCore.App.Runtime.linux-armMicrosoft.AspNetCore.App.Runtime.linux-arm64Microsoft.AspNetCore.App.Runtime.linux-musl-armMicrosoft.AspNetCore.App.Runtime.linux-musl-arm64Microsoft.AspNetCore.App.Runtime.linux-musl-x64Microsoft.AspNetCore.App.Runtime.linux-x64Microsoft.AspNetCore.App.Runtime.osx-arm64Microsoft.AspNetCore.App.Runtime.osx-x64Microsoft.AspNetCore.App.Runtime.win-arm
CVE-2025-330738.8v3.1ACTIVE
26.4
Windows 10 Version 1507Windows 10 Version 1607Windows 10 Version 1809Windows 10 Version 21H2Windows 10 Version 22H2Windows 11 version 22H2Windows 11 version 22H3Windows 11 Version 23H2Windows 11 Version 24H2Windows Server 2008 R2 Service Pack 1
CVE-2025-249898.2v3.1ACTIVE
31.2
Microsoft Power Pages
CVE-2025-212989.8v3.1POC
0.0
Windows 10 Version 1507Windows 10 Version 1607Windows 10 Version 1809Windows 10 Version 21H2Windows 10 Version 22H2Windows 11 version 22H2Windows 11 version 22H3Windows 11 Version 23H2Windows 11 Version 24H2Windows Server 2008 R2 Service Pack 1
CVE-2024-490407.5v3.1POC
0.0
Microsoft Exchange Server 2016 Cumulative Update 23Microsoft Exchange Server 2019 Cumulative Update 13Microsoft Exchange Server 2019 Cumulative Update 14
CVE-2024-381398.7v3.1POC
0.0
Microsoft Dataverse
CVE-2024-381908.6v3.1POC
0.0
Microsoft Power Platform
CVE-2024-382047.5v3.1POC
0.0
Microsoft Azure Functions
CVE-2024-434689.8v3.1ACTIVE
40.6
Microsoft Configuration Manager
CVE-2024-380639.8v3.1POC
0.0
Windows 10 Version 1507Windows 10 Version 1607Windows 10 Version 1809Windows 10 Version 21H2Windows 10 Version 22H2Windows 11 version 21H2Windows 11 version 22H2Windows 11 version 22H3Windows 11 Version 23H2Windows 11 Version 24H2
CVE-2024-380947.2v3.1ACTIVE
24.0
Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019Microsoft SharePoint Server Subscription Edition
CVE-2024-300536.5v3.1POC
0.0
Azure Migrate
CVE-2024-290538.8v3.1POC
0.0
Microsoft Defender for IoT
CVE-2024-290597.5v3.1ACTIVE
40.6
Microsoft .NET Framework
CVE-2024-213927.5v3.1POC
0.0
.NETMicrosoft Visual Studio 2022 version 17.4Microsoft Visual Studio 2022 version 17.6Microsoft Visual Studio 2022 version 17.8Microsoft Visual Studio 2022 version 17.9PowerShell 7.3PowerShell 7.4
CVE-2024-214009.0v3.1POC
0.0
Azure Kubernetes Service
CVE-2024-214047.5v3.1POC
0.0
.NETMicrosoft Visual Studio 2022 version 17.4Microsoft Visual Studio 2022 version 17.6Microsoft Visual Studio 2022 version 17.8
CVE-2024-214109.8v3.1ACTIVE
40.6
Microsoft Exchange Server 2016 Cumulative Update 23Microsoft Exchange Server 2019 Cumulative Update 13Microsoft Exchange Server 2019 Cumulative Update 14
CVE-2024-214139.8v3.1ACTIVE
40.6
Microsoft 365 Apps for EnterpriseMicrosoft Office 2016Microsoft Office 2019Microsoft Office LTSC 2021
CVE-2023-360388.2v3.1POC
0.0
.NETASP.NET CoreMicrosoft Visual Studio 2022 version 17.2Microsoft Visual Studio 2022 version 17.4Microsoft Visual Studio 2022 version 17.6Microsoft Visual Studio 2022 version 17.7
CVE-2023-417635.3v3.1ACTIVE
40.6
Skype for Business Server 2015 CU13Skype for Business Server 2019 CU7
CVE-2023-368737.4v3.1POC
0.0
Microsoft .NET Framework
CVE-2023-381807.5v3.1ACTIVE
40.6
.NETASP.NET CoreMicrosoft Visual Studio 2022 version 17.2Microsoft Visual Studio 2022 version 17.4Microsoft Visual Studio 2022 version 17.6
Each CVE: 10 pts base (Active only), boosted by:
KEV×2.0AC: Low×1.2PR: None×1.3PR: Low×1.1Auto×1.3