56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-26196 | MED 4.3 | microsoft edge Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability | 1.2% | — |
| CVE-2023-24900 | MED 5.9 | microsoft windows_10_1507 Windows NTLM Security Support Provider Information Disclosure Vulnerability | 1.2% | — |
| CVE-2020-0634 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'. | 1.2% | — |
| CVE-2024-21399 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2022-30148 | MED 5.5 | microsoft windows_10 Windows Desired State Configuration (DSC) Information Disclosure Vulnerability | 1.2% | — |
| CVE-2022-29114 | MED 5.5 | microsoft windows_10 Windows Print Spooler Information Disclosure Vulnerability | 1.2% | — |
| CVE-2024-43487 | MED 6.5 | microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2023-36804 | HIGH 7.8 | microsoft windows_10_1507 Windows GDI Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2021-1648 | HIGH 7.8 | microsoft windows_10 Microsoft splwow64 Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2020-1455 | MED 5.3 | microsoft sql_server_management_studio A denial of service vulnerability exists when Microsoft SQL Server Management Studio (SSMS) improperly handles files. An attacker could exploit the vulnerability to trigger a denial of service. To exploit the vulnerability, an attacker would first require exec | 1.2% | — |
| CVE-2010-0485 | HIGH 7.8 | microsoft windows_2000 The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 "do not properly validate all callback parameters when creating a new windo | 1.2% | — |
| CVE-2022-21895 | HIGH 7.8 | microsoft windows_10 Windows User Profile Service Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2021-43242 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.2% | — |
| CVE-2022-35753 | HIGH 8.1 | microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2022-35752 | HIGH 8.1 | microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2022-35745 | HIGH 8.1 | microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2021-38642 | MED 6.1 | microsoft edge Microsoft Edge for iOS Spoofing Vulnerability | 1.2% | — |
| CVE-2021-38641 | MED 6.1 | microsoft edge Microsoft Edge for Android Spoofing Vulnerability | 1.2% | — |
| CVE-2025-33051 | HIGH 7.5 | microsoft exchange_server Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. | 1.2% | — |
| CVE-2024-43600 | HIGH 7.8 | microsoft office Microsoft Office Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2021-31978 | MED 5.5 | microsoft malware_protection_engine Microsoft Defender Denial of Service Vulnerability | 1.2% | — |
| CVE-2020-1420 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when Windows Error Reporting improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Error Reporting Information Disclosu | 1.2% | — |
| CVE-2020-1358 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Resource Policy component improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Resource Policy Information Dis | 1.2% | — |
| CVE-2020-1426 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, CVE-2020-1389, CVE-2020-1419. | 1.2% | — |
| CVE-2020-1391 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Agent Activation Runtime (AarSvc) fails to properly handle objects in memory, aka 'Windows Agent Activation Runtime Information Disclosure Vulnerability'. | 1.2% | — |