58.507 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.469 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-41125 | HIGH 7.8 | microsoft windows_10_1507 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | 3.0% | |
| CVE-2026-50522 | CRIT 9.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | 3.0% | |
| CVE-2018-8589 | HIGH 7.8 | microsoft windows_7 An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. | 3.0% | |
| CVE-2021-31199 | MED 5.2 | microsoft windows_10_1507 Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | 3.0% | |
| CVE-2021-38649 | HIGH 7.0 | microsoft azure_automation_state_configuration Open Management Infrastructure Elevation of Privilege Vulnerability | 2.9% | |
| CVE-2021-38645 | HIGH 7.8 | microsoft azure_automation_state_configuration Open Management Infrastructure Elevation of Privilege Vulnerability | 2.7% | |
| CVE-2026-45659 | HIGH 8.8 | ransomware microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2.7% | |
| CVE-2020-0878 | MED 4.2 | ransomware microsoft chakracore <p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker | 2.7% | |
| CVE-2024-38226 | HIGH 7.3 | microsoft office_2019 Microsoft Publisher Security Feature Bypass Vulnerability | 2.7% | |
| CVE-2025-59230 | HIGH 7.8 | microsoft windows_10_1507 Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 2.7% | |
| CVE-2021-31201 | MED 5.2 | microsoft windows_10_1507 Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability | 2.6% | |
| CVE-2025-62221 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 2.5% | |
| CVE-2022-41049 | MED 5.4 | microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability | 2.5% | |
| CVE-2026-21519 | HIGH 7.8 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 2.5% | |
| CVE-2022-21919 | HIGH 7.0 | microsoft windows_10_1507 Windows User Profile Service Elevation of Privilege Vulnerability | 2.4% | |
| CVE-2020-0638 | HIGH 7.8 | ransomware microsoft windows_10_1709 An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege | 2.4% | |
| CVE-2025-21391 | HIGH 7.1 | microsoft windows_10_1507 Windows Storage Elevation of Privilege Vulnerability | 2.3% | |
| CVE-2025-32706 | HIGH 7.8 | microsoft windows_10_1507 Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 2.3% | |
| CVE-2019-0880 | HIGH 7.8 | microsoft windows_10_1507 A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'. | 2.3% | |
| CVE-2022-41073 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability | 2.3% | |
| CVE-2025-24993 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | 2.2% | |
| CVE-2025-32709 | HIGH 7.8 | microsoft windows_10_1507 Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 2.1% | |
| CVE-2026-65660 | HIGH 8.8 | microsoft sharepoint_server Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2.1% | |
| CVE-2025-24991 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | 2.0% | |
| CVE-2025-24984 | MED 4.6 | microsoft windows_10_1507 Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. | 2.0% |