58.507 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.469 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-38193 | HIGH 7.8 | microsoft windows_10_1507 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 28.5% | |
| CVE-2022-37969 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 28.3% | |
| CVE-2023-36802 | HIGH 7.8 | microsoft windows_10_1809 Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability | 27.9% | |
| CVE-2024-21351 | HIGH 7.6 | microsoft windows_10_1507 Windows SmartScreen Security Feature Bypass Vulnerability | 27.8% | |
| CVE-2018-8581 | HIGH 7.4 | ransomware microsoft exchange_server An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. | 27.4% | |
| CVE-2025-30397 | HIGH 7.5 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network. | 26.8% | |
| CVE-2014-2817 | HIGH 8.8 | microsoft internet_explorer Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability." | 26.3% | |
| CVE-2016-3351 | MED 6.5 | ransomware microsoft edge Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." | 26.3% | |
| CVE-2024-49138 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 26.2% | |
| CVE-2024-35250 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 25.2% | |
| CVE-2022-41128 | HIGH 8.8 | microsoft windows_10_1507 Windows Scripting Languages Remote Code Execution Vulnerability | 24.6% | |
| CVE-2016-0040 | HIGH 7.8 | microsoft windows_7 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability." | 24.5% | |
| CVE-2026-21510 | HIGH 8.8 | microsoft windows_10_1607 Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | 24.2% | |
| CVE-2020-1380 | HIGH 7.8 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current u | 24.2% | |
| CVE-2021-36948 | HIGH 7.8 | microsoft windows_10_1809 Windows Update Medic Service Elevation of Privilege Vulnerability | 23.3% | |
| CVE-2017-0210 | HIGH 8.8 | microsoft internet_explorer An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Pr | 22.3% | |
| CVE-2025-14174 | HIGH 8.8 | apple ipados Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) | 22.3% | |
| CVE-2021-31956 | HIGH 7.8 | microsoft windows_10_1507 Windows NTFS Elevation of Privilege Vulnerability | 22.3% | |
| CVE-2018-8639 | HIGH 7.8 | ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 20 | 22.2% | |
| CVE-2016-0162 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability." | 22.0% | |
| CVE-2021-34484 | HIGH 7.8 | microsoft windows_10_1507 Windows User Profile Service Elevation of Privilege Vulnerability | 21.8% | |
| CVE-2019-1297 | HIGH 8.8 | microsoft excel A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | 21.8% | |
| CVE-2019-0903 | HIGH 8.8 | microsoft windows_10_1507 A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. | 21.7% | |
| CVE-2023-29360 | HIGH 8.4 | microsoft windows_10_1607 Microsoft Streaming Service Elevation of Privilege Vulnerability | 21.6% | |
| CVE-2024-7971 | CRIT 9.6 | google chrome Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 21.1% |