58.507 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.469 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-0165 | HIGH 7.8 | microsoft windows_10_1507 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application | 13.7% | |
| CVE-2024-38213 | MED 6.5 | microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability | 13.6% | |
| CVE-2024-21410 | CRIT 9.8 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 12.6% | |
| CVE-2023-36424 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 12.2% | |
| CVE-2023-21715 | HIGH 7.3 | microsoft 365_apps Microsoft Publisher Security Feature Bypass Vulnerability | 12.0% | |
| CVE-2023-36033 | HIGH 7.8 | microsoft windows_10_1809 Windows DWM Core Library Elevation of Privilege Vulnerability | 12.0% | |
| CVE-2019-1253 | HIGH 7.8 | ransomware microsoft windows_10_1703 An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerab | 11.6% | |
| CVE-2021-38648 | HIGH 7.8 | microsoft azure_automation_state_configuration Open Management Infrastructure Elevation of Privilege Vulnerability | 11.4% | |
| CVE-2017-0005 | HIGH 7.8 | microsoft windows_10_1507 The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a | 11.0% | |
| CVE-2023-23376 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 10.9% | |
| CVE-2022-26925 | HIGH 8.1 | microsoft windows_10_1507 Windows LSA Spoofing Vulnerability | 10.5% | |
| CVE-2021-43890 | HIGH 7.1 | ransomware microsoft app_installer We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emo | 10.3% | |
| CVE-2021-33771 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 10.2% | |
| CVE-2015-2546 | HIGH 8.2 | ransomware microsoft windows_10_1507 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted appli | 10.1% | |
| CVE-2023-32046 | HIGH 7.8 | microsoft windows_10_1507 Windows MSHTML Platform Elevation of Privilege Vulnerability | 10.0% | |
| CVE-2017-0263 | HIGH 7.8 | microsoft windows_10_1507 The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted | 10.0% | |
| CVE-2024-38217 | MED 5.4 | microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability | 10.0% | |
| CVE-2025-21333 | HIGH 7.8 | microsoft windows_10_21h2 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | 10.0% | |
| CVE-2019-1132 | HIGH 7.8 | microsoft windows_7 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. | 9.8% | |
| CVE-2019-0703 | MED 6.5 | microsoft windows_10_1507 An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821. | 9.6% | |
| CVE-2021-34486 | HIGH 7.8 | microsoft windows_10_1809 Windows Event Tracing Elevation of Privilege Vulnerability | 9.3% | |
| CVE-2010-4398 | HIGH 7.8 | microsoft windows_7 Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges | 8.7% | |
| CVE-2019-1388 | HIGH 7.8 | ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'. | 8.6% | |
| CVE-2021-28310 | HIGH 7.8 | microsoft windows_10_1803 Win32k Elevation of Privilege Vulnerability | 8.3% | |
| CVE-2024-38189 | HIGH 8.8 | microsoft 365_apps Microsoft Project Remote Code Execution Vulnerability | 8.2% |