56.696 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-49126 | HIGH 8.1 | microsoft windows_10_1507 Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2024-20689 | HIGH 7.1 | microsoft windows_server_2012 Secure Boot Security Feature Bypass Vulnerability | 1.3% | — |
| CVE-2024-20688 | HIGH 7.1 | microsoft windows_server_2012 Secure Boot Security Feature Bypass Vulnerability | 1.3% | — |
| CVE-2020-0981 | HIGH 8.8 | microsoft windows_10 A security feature bypass vulnerability exists when Windows fails to properly handle token relationships.An attacker who successfully exploited the vulnerability could allow an application with a certain integrity level to execute code at a different integrity | 1.3% | — |
| CVE-2020-16986 | MED 6.2 | microsoft azure_sphere Azure Sphere Denial of Service Vulnerability | 1.3% | — |
| CVE-2024-30082 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2025-29835 | MED 6.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.3% | — |
| CVE-2025-29832 | MED 6.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.3% | — |
| CVE-2025-29830 | MED 6.5 | microsoft windows_10_1507 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.3% | — |
| CVE-2025-21286 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2025-21282 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2025-21273 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2025-21266 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2024-21390 | HIGH 7.1 | microsoft authenticator Microsoft Authenticator Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2023-33144 | MED 6.6 | microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability | 1.3% | — |
| CVE-2018-0963 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. | 1.3% | — |
| CVE-2024-38129 | HIGH 7.5 | microsoft windows_server_2022_23h2 Windows Kerberos Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2019-1053 | MED 6.3 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would | 1.3% | — |
| CVE-2024-38011 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.3% | — |
| CVE-2024-37987 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.3% | — |
| CVE-2024-37975 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.3% | — |
| CVE-2012-0180 | HIGH 7.8 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input pass | 1.3% | — |
| CVE-2017-8468 | HIGH 7.8 | microsoft windows_10 Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to run processes in an elevated context when the Windows kernel improperly handles objects in memory, aka "Win32k | 1.3% | — |
| CVE-2009-2508 | MED 6.9 | microsoft windows_server_2003 The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers | 1.3% | — |
| CVE-2020-1361 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the way that the WalletService handles memory.To exploit the vulnerability, an attacker would first need code execution on a victim system, aka 'Windows WalletService Information Disclosure Vulnerability'. | 1.3% | — |