IT
58.507 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.469 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-30400 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. 1.9%
CVE-2019-0797 HIGH 7.8 microsoft windows_10_1507 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0808. 1.9%
CVE-2022-41091 MED 5.4 ransomware microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability 1.8%
CVE-2019-1129 HIGH 7.8 ransomware microsoft windows_10_1703 An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130. 1.8%
CVE-2019-1130 HIGH 7.8 ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129. 1.7%
CVE-2022-41033 HIGH 7.8 microsoft windows_10_1507 Windows COM+ Event System Service Elevation of Privilege Vulnerability 1.7%
CVE-2023-28229 HIGH 7.0 microsoft windows_10_1507 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability 1.7%
CVE-2024-38107 HIGH 7.8 microsoft windows_10_1507 Windows Power Dependency Coordinator Elevation of Privilege Vulnerability 1.6%
CVE-2025-24989 HIGH 8.2 microsoft power_pages An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected cust 1.6%
CVE-2026-33824 CRIT 9.8 microsoft windows_10_1607 Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. 1.6%
CVE-2021-41357 HIGH 7.8 microsoft windows_10_2004 Win32k Elevation of Privilege Vulnerability 1.6%
CVE-2021-40450 HIGH 7.8 microsoft windows_10_1809 Win32k Elevation of Privilege Vulnerability 1.6%
CVE-2026-21514 HIGH 7.8 microsoft 365_apps Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. 1.6%
CVE-2025-21418 HIGH 7.8 microsoft windows_10_1607 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 1.6%
CVE-2025-21334 HIGH 7.8 microsoft windows_10_21h2 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability 1.6%
CVE-2019-1214 HIGH 7.8 microsoft windows_10_1507 An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'. 1.4%
CVE-2025-32701 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 1.4%
CVE-2025-21335 HIGH 7.8 microsoft windows_10_21h2 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability 1.4%
CVE-2025-24983 HIGH 7.0 microsoft windows_10_1507 Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. 1.3%
CVE-2024-49035 HIGH 8.7 microsoft partner_center An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. 1.3%
CVE-2026-45498 MED 4.0 microsoft defender_antimalware_platform Microsoft Defender Denial of Service Vulnerability 1.3%
CVE-2026-56164 MED 5.3 microsoft sharepoint_server Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. 1.0%
CVE-2026-32201 MED 6.5 microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 1.0%
CVE-2026-42897 HIGH 8.1 microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2026-41091 HIGH 7.8 microsoft malware_protection_engine Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. 0.4%