58.507 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.469 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-0676 | MED 6.5 | microsoft internet_explorer An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vul | 8.1% | |
| CVE-2021-38646 | HIGH 7.8 | ransomware microsoft 365_apps Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability | 8.0% | |
| CVE-2025-5419 | HIGH 8.8 | google chrome Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 7.8% | |
| CVE-2020-0683 | HIGH 7.8 | microsoft windows_10_1507 An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686. | 7.6% | |
| CVE-2020-1040 | CRIT 9.0 | microsoft windows_server_2008 A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is un | 7.4% | |
| CVE-2004-0210 | HIGH 7.8 | microsoft interix The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow. | 7.2% | |
| CVE-2026-20805 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. | 7.2% | |
| CVE-2024-38080 | HIGH 7.8 | microsoft windows_11_21h2 Windows Hyper-V Elevation of Privilege Vulnerability | 7.1% | |
| CVE-2022-24521 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 7.1% | |
| CVE-2019-1064 | HIGH 7.8 | ransomware microsoft windows_10_1607 An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install pr | 6.9% | |
| CVE-2021-33739 | HIGH 8.4 | microsoft windows_10_1909 Microsoft DWM Core Library Elevation of Privilege Vulnerability | 6.6% | |
| CVE-2025-24990 | HIGH 7.8 | microsoft windows_10_1507 Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumula | 6.4% | |
| CVE-2024-38106 | HIGH 7.0 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 6.3% | |
| CVE-2024-38014 | HIGH 7.8 | microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability | 6.3% | |
| CVE-2019-1069 | HIGH 7.8 | ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an | 6.1% | |
| CVE-2021-27059 | HIGH 7.6 | microsoft office Microsoft Office Remote Code Execution Vulnerability | 6.1% | |
| CVE-2025-62215 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally. | 6.0% | |
| CVE-2016-0167 | HIGH 7.8 | ransomware microsoft windows_10_1507 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application | 5.7% | |
| CVE-2024-30051 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows DWM Core Library Elevation of Privilege Vulnerability | 5.6% | |
| CVE-2023-21823 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Remote Code Execution Vulnerability | 5.6% | |
| CVE-2021-27085 | HIGH 8.8 | microsoft internet_explorer Internet Explorer Remote Code Execution Vulnerability | 5.4% | |
| CVE-2020-17087 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Local Elevation of Privilege Vulnerability | 5.4% | |
| CVE-2019-0863 | HIGH 7.8 | microsoft windows_10_1507 An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. | 5.2% | |
| CVE-2015-6175 | HIGH 7.8 | microsoft windows_10_1507 The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability." | 5.1% | |
| CVE-2025-47827 | MED 4.6 | igel igel_os In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image. | 4.9% |