56.667 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1378 | HIGH 7.8 | microsoft windows_10_update_assistant An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows 10 Update Assistant Elevation of Privilege V | 1.3% | — |
| CVE-2026-59132 | HIGH 7.5 | microsoft windows_10_1607 Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. | 1.3% | — |
| CVE-2020-17056 | MED 5.5 | microsoft windows_10 Windows Network File System Information Disclosure Vulnerability | 1.3% | — |
| CVE-2020-17013 | MED 5.5 | microsoft windows_10 Win32k Information Disclosure Vulnerability | 1.3% | — |
| CVE-2020-17004 | MED 5.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 1.3% | — |
| CVE-2020-17000 | MED 5.5 | microsoft windows_10 Remote Desktop Protocol Client Information Disclosure Vulnerability | 1.3% | — |
| CVE-2020-16999 | MED 5.5 | microsoft windows_10 Windows WalletService Information Disclosure Vulnerability | 1.3% | — |
| CVE-2020-0775 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when Windows Error Reporting improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Error Reporting Information Disclosu | 1.3% | — |
| CVE-2019-1294 | MED 4.6 | microsoft windows_10 A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'. | 1.3% | — |
| CVE-2016-3300 | HIGH 7.8 | microsoft windows_8.1 The Netlogon service in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 improperly establishes secure communications channels, which allows local users to gain privileges by leveraging access to a domain-joined machine, aka "Netlogon | 1.3% | — |
| CVE-2021-31982 | HIGH 8.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 1.3% | — |
| CVE-2020-1194 | MED 5.5 | microsoft windows_10 A denial of service vulnerability exists when Windows Registry improperly handles filesystem operations, aka 'Windows Registry Denial of Service Vulnerability'. | 1.3% | — |
| CVE-2020-0859 | MED 5.5 | microsoft windows_10 An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'. | 1.3% | — |
| CVE-2020-0643 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI+ Information Disclosure Vulnerabil | 1.3% | — |
| CVE-2020-0639 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'. This CVE ID is unique from | 1.3% | — |
| CVE-2020-0608 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. | 1.3% | — |
| CVE-2019-1409 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Remote Procedure Call (RPC) runtime improperly initializes objects in memory, aka 'Windows Remote Procedure Call Information Disclosure Vulnerability'. | 1.3% | — |
| CVE-2025-21408 | HIGH 8.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2026-63520 | HIGH 8.1 | microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | 1.3% | — |
| CVE-2023-38186 | HIGH 8.8 | microsoft windows_10_21h2 Windows Mobile Device Management Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2024-30020 | HIGH 8.1 | microsoft windows_10_1507 Windows Cryptographic Services Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2017-8624 | HIGH 7.8 | microsoft windows_10 CLFS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it handles objects | 1.3% | — |
| CVE-2017-8622 | HIGH 7.8 | microsoft windows_10 Windows Subsystem for Linux in Windows 10 1703 allows an elevation of privilege vulnerability when it fails to properly handle handles NT pipes, aka "Windows Subsystem for Linux Elevation of Privilege Vulnerability". | 1.3% | — |
| CVE-2020-16984 | HIGH 7.3 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1.3% | — |
| CVE-2019-0936 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0734. | 1.3% | — |