56.704 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-16919 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows Enterprise App Management Service improperly handles certain file operations. An attacker who successfully exploited this vulnerability could read arbitrary files.</p> <p>An attacker with unpri | 1.3% | — |
| CVE-2018-1009 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles objects in memory and incorrectly maps kernel memory, aka "Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Wi | 1.3% | — |
| CVE-2026-24300 | CRIT 9.8 | microsoft azure_front_door Azure Front Door Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2022-30200 | HIGH 7.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2025-26628 | HIGH 7.3 | microsoft azure_local_cluster Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally. | 1.3% | — |
| CVE-2024-29050 | HIGH 8.4 | microsoft windows_10_1507 Windows Cryptographic Services Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2018-8592 | MED 6.4 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physical media (USB, DVD, etc, aka "Windows Elevation Of Privilege Vulnerability." This affects Windows 10, Windows Server 2019. | 1.3% | — |
| CVE-2018-8412 | HIGH 7.8 | microsoft office_for_mac An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka "Microsoft (MAU) Office Elevation of Privilege Vulnerability." This affects Microsoft Office. | 1.2% | — |
| CVE-2026-33096 | HIGH 7.5 | microsoft windows_11_23h2 Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2024-30045 | MED 6.3 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2018-8347 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows when the Windows kernel fails to properly handle parsing of certain symbolic links, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Win | 1.2% | — |
| CVE-2018-8124 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 20 | 1.2% | — |
| CVE-2005-2765 | LOW 2.1 | microsoft windows_2003_server The user interface in the Windows Firewall does not properly display certain malformed entries in the Windows Registry, which makes it easier for attackers with administrator privileges to hide activities if the administrator only uses the Windows Firewall int | 1.2% | — |
| CVE-2020-16961 | HIGH 7.8 | microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2020-16960 | HIGH 7.8 | microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2017-8576 | HIGH 7.0 | microsoft windows_10 The graphics component in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to run arbitrary code in kernel mode via a specially crafted application, aka "Microsoft Graphics Component Elevation of Privilege V | 1.2% | — |
| CVE-2022-22035 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2020-1116 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the use | 1.2% | — |
| CVE-2020-1072 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerabili | 1.2% | — |
| CVE-2026-21248 | HIGH 7.3 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | 1.2% | — |
| CVE-2026-21244 | HIGH 7.3 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | 1.2% | — |
| CVE-2025-21173 | HIGH 7.3 | microsoft .net .NET Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2022-37962 | HIGH 7.8 | microsoft 365_apps Microsoft PowerPoint Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2020-16897 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p | 1.2% | — |
| CVE-2022-34704 | MED 4.7 | microsoft windows_10 Windows Defender Credential Guard Information Disclosure Vulnerability | 1.2% | — |