58.507 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.469 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-30400 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. | 1.9% | |
| CVE-2019-0797 | HIGH 7.8 | microsoft windows_10_1507 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0808. | 1.9% | |
| CVE-2022-41091 | MED 5.4 | ransomware microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability | 1.8% | |
| CVE-2019-1129 | HIGH 7.8 | ransomware microsoft windows_10_1703 An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130. | 1.8% | |
| CVE-2019-1130 | HIGH 7.8 | ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129. | 1.7% | |
| CVE-2022-41033 | HIGH 7.8 | microsoft windows_10_1507 Windows COM+ Event System Service Elevation of Privilege Vulnerability | 1.7% | |
| CVE-2023-28229 | HIGH 7.0 | microsoft windows_10_1507 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability | 1.7% | |
| CVE-2024-38107 | HIGH 7.8 | microsoft windows_10_1507 Windows Power Dependency Coordinator Elevation of Privilege Vulnerability | 1.6% | |
| CVE-2025-24989 | HIGH 8.2 | microsoft power_pages An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected cust | 1.6% | |
| CVE-2026-33824 | CRIT 9.8 | microsoft windows_10_1607 Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. | 1.6% | |
| CVE-2021-41357 | HIGH 7.8 | microsoft windows_10_2004 Win32k Elevation of Privilege Vulnerability | 1.6% | |
| CVE-2021-40450 | HIGH 7.8 | microsoft windows_10_1809 Win32k Elevation of Privilege Vulnerability | 1.6% | |
| CVE-2026-21514 | HIGH 7.8 | microsoft 365_apps Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. | 1.6% | |
| CVE-2025-21418 | HIGH 7.8 | microsoft windows_10_1607 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 1.6% | |
| CVE-2025-21334 | HIGH 7.8 | microsoft windows_10_21h2 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | 1.6% | |
| CVE-2019-1214 | HIGH 7.8 | microsoft windows_10_1507 An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'. | 1.4% | |
| CVE-2025-32701 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 1.4% | |
| CVE-2025-21335 | HIGH 7.8 | microsoft windows_10_21h2 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | 1.4% | |
| CVE-2025-24983 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. | 1.3% | |
| CVE-2024-49035 | HIGH 8.7 | microsoft partner_center An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. | 1.3% | |
| CVE-2026-45498 | MED 4.0 | microsoft defender_antimalware_platform Microsoft Defender Denial of Service Vulnerability | 1.3% | |
| CVE-2026-56164 | MED 5.3 | microsoft sharepoint_server Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. | 1.0% | |
| CVE-2026-32201 | MED 6.5 | microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 1.0% | |
| CVE-2026-42897 | HIGH 8.1 | microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 0.5% | |
| CVE-2026-41091 | HIGH 7.8 | microsoft malware_protection_engine Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. | 0.4% |