56.571 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.454 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-26420 | HIGH 7.1 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 3.0% | — |
| CVE-2010-1894 | HIGH 7.2 | microsoft windows_2003_server The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly handle unspecified exceptions, which allows local users to gain privileges via a crafted application, aka "Win32k Exception Handling | 3.0% | — |
| CVE-2020-1295 | HIGH 8.8 | microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. | 3.0% | — |
| CVE-2025-59512 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally. | 3.0% | — |
| CVE-2017-8642 | MED 6.1 | microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to elevate privileges due to the way that Microsoft Edge validates JavaScript under specific conditions, aka "Microsoft Edge Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-20 | 3.0% | — |
| CVE-2025-21197 | MED 6.5 | microsoft windows_10_1507 Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content. | 2.9% | — |
| CVE-2014-0323 | MED 6.6 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow | 2.9% | — |
| CVE-2022-24541 | HIGH 8.8 | microsoft windows_10 Windows Server Service Remote Code Execution Vulnerability | 2.9% | — |
| CVE-2022-21988 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 2.9% | — |
| CVE-2021-41352 | HIGH 7.5 | microsoft system_center_operations_manager SCOM Information Disclosure Vulnerability | 2.9% | — |
| CVE-2017-0103 | HIGH 7.0 | microsoft windows_7 The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 mishandles registry objects in memory, which allows local users to gain privileges via a crafted application, aka "Windows Registry Elevat | 2.9% | — |
| CVE-2022-37973 | HIGH 7.7 | microsoft windows_10 Windows Local Session Manager (LSM) Denial of Service Vulnerability | 2.9% | — |
| CVE-2021-31174 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 2.9% | — |
| CVE-2021-31946 | HIGH 7.8 | microsoft paint_3d Paint 3D Remote Code Execution Vulnerability | 2.9% | — |
| CVE-2024-43484 | HIGH 7.5 | microsoft .net .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | 2.9% | — |
| CVE-2021-31941 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 2.9% | — |
| CVE-2020-0902 | CRIT 9.8 | microsoft service_fabric An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions, aka 'Service Fabric Elevation of Privilege'. | 2.9% | — |
| CVE-2023-35618 | CRIT 9.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 2.9% | — |
| CVE-2018-7250 | MED 5.5 | microsoft windows_7 An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. An uninitialized kernel pool allocation in IOCTL 0xCA002813 allows a local unprivileged | 2.9% | — |
| CVE-2023-28244 | HIGH 8.1 | microsoft windows_server_2008 Windows Kerberos Elevation of Privilege Vulnerability | 2.9% | — |
| CVE-2021-27079 | MED 5.7 | microsoft windows_10 Windows Media Photo Codec Information Disclosure Vulnerability | 2.9% | — |
| CVE-2020-17150 | HIGH 7.8 | microsoft tslint Visual Studio Code Remote Code Execution Vulnerability | 2.9% | — |
| CVE-2021-27052 | MED 5.3 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Information Disclosure Vulnerability | 2.9% | — |
| CVE-2024-30105 | HIGH 7.5 | microsoft .net .NET and Visual Studio Denial of Service Vulnerability | 2.9% | — |
| CVE-2021-31214 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 2.9% | — |