56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1304 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE | 3.3% | — |
| CVE-2020-1282 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE | 3.3% | — |
| CVE-2020-16937 | MED 4.7 | microsoft .net_framework <p>An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attacker who successfully exploited the vulnerability could disclose contents of an affected system's memory.</p> <p>To exploit the vulnerability | 3.3% | — |
| CVE-2024-20677 | HIGH 7.8 | microsoft 365_apps A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX files has been disabled in Word, Excel, PowerPoint and Outlook for Windows and Mac. Versions of Office that had this feat | 3.3% | — |
| CVE-2021-31936 | HIGH 7.4 | microsoft accessibility_insights_for_web Microsoft Accessibility Insights for Web Information Disclosure Vulnerability | 3.3% | — |
| CVE-2018-8454 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when Windows Audio Service fails to properly handle objects in memory, aka "Windows Audio Service Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019. | 3.3% | — |
| CVE-2016-7220 | LOW 3.3 | microsoft windows_10 Virtual Secure Mode in Microsoft Windows 10 allows local users to obtain sensitive information via a crafted application, aka "Virtual Secure Mode Information Disclosure Vulnerability." | 3.3% | — |
| CVE-2025-27740 | HIGH 8.8 | microsoft windows_server_2008 Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network. | 3.3% | — |
| CVE-2022-34724 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability | 3.3% | — |
| CVE-2021-24112 | HIGH 8.1 | microsoft .net .NET Core Remote Code Execution Vulnerability | 3.3% | — |
| CVE-2022-26924 | HIGH 7.5 | microsoft yet_another_reverse_proxy YARP Denial of Service Vulnerability | 3.3% | — |
| CVE-2020-1061 | HIGH 7.5 | microsoft windows_10 A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attac | 3.3% | — |
| CVE-2021-36960 | HIGH 7.5 | microsoft windows_10 Windows SMB Information Disclosure Vulnerability | 3.3% | — |
| CVE-2020-1112 | HIGH 8.5 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content. An attacker who successfully exploited this vulnerability could upload restricted file types to an II | 3.3% | — |
| CVE-2018-8470 | MED 6.1 | microsoft internet_explorer A security feature bypass vulnerability exists in Internet Explorer due to how scripts are handled that allows a universal cross-site scripting (UXSS) condition, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11. | 3.3% | — |
| CVE-2020-0908 | HIGH 7.5 | microsoft windows_10 <p>A remote code execution vulnerability exists when the Windows Text Service Module improperly handles memory. An attacker who successfully exploited the vulnerability could gain execution on a victim system.</p> <p>An attacker could host a specially crafted | 3.3% | — |
| CVE-2020-1509 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LSASS) when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could caus | 3.3% | — |
| CVE-2020-0692 | HIGH 8.1 | microsoft exchange_server An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. | 3.3% | — |
| CVE-2019-1457 | HIGH 7.8 | microsoft office A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document, aka 'Microsoft Office Excel Security Feature Bypass'. | 3.3% | — |
| CVE-2015-2553 | HIGH 7.2 | microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles junctions during mountpoint creation, which makes it easie | 3.3% | — |
| CVE-2017-8551 | MED 6.1 | microsoft project_server An elevation of privilege vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Microsoft SharePoint XSS vulnerability". | 3.3% | — |
| CVE-2023-35638 | HIGH 7.5 | microsoft windows_server_2012 DHCP Server Service Denial of Service Vulnerability | 3.3% | — |
| CVE-2024-38147 | HIGH 7.8 | microsoft windows_10_21h2 Microsoft DWM Core Library Elevation of Privilege Vulnerability | 3.3% | — |
| CVE-2015-6171 | HIGH 7.2 | microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted app | 3.3% | — |
| CVE-2008-4510 | MED 4.9 | microsoft windows_vista Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page fault and system crash) via multiple attempts to access a virtual address in a PAGE_NOACCESS memory page. | 3.3% | — |