56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-1670 | MED 5.5 | microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability | 1.2% | — |
| CVE-2021-1663 | MED 5.5 | microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability | 1.2% | — |
| CVE-2021-1637 | MED 5.5 | microsoft windows_10 Windows DNS Query Information Disclosure Vulnerability | 1.2% | — |
| CVE-2026-20921 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 1.2% | — |
| CVE-2002-0725 | MED 5.5 | microsoft windows_2000 NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit trail instead of the target file. | 1.2% | — |
| CVE-2021-26892 | MED 6.2 | microsoft windows_10 Windows Extensible Firmware Interface Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2018-0868 | HIGH 7.0 | microsoft windows_10 Windows Installer in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privi | 1.2% | — |
| CVE-2021-28483 | CRIT 9.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2020-17134 | HIGH 7.8 | microsoft windows_10 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2025-49666 | HIGH 7.2 | microsoft windows_server_2016 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network. | 1.2% | — |
| CVE-2026-42898 | CRIT 9.9 | microsoft dynamics_365 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | 1.2% | — |
| CVE-2025-32714 | HIGH 7.8 | microsoft windows_10_1507 Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally. | 1.2% | — |
| CVE-2024-43613 | HIGH 7.2 | microsoft azure_database_for_postgresql_flexible_server Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2022-21931 | MED 4.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2022-21930 | MED 4.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2018-8561 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server | 1.2% | — |
| CVE-2018-8485 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server | 1.2% | — |
| CVE-2018-8471 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Microsoft RemoteFX Virtual GPU miniport driver handles objects in memory, aka "Microsoft RemoteFX Virtual GPU miniport driver Elevation of Privilege Vulnerability." This affects Windows Server | 1.2% | — |
| CVE-2018-8343 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it, aka "Windows NDIS Elevation of Privilege Vulnerability." This affects Windows | 1.2% | — |
| CVE-2018-8342 | HIGH 7.8 | microsoft windows_7 An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it, aka "Windows NDIS Elevation of Privilege Vulnerability." This affects Windows | 1.2% | — |
| CVE-2024-49108 | HIGH 8.1 | microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2024-49106 | HIGH 8.1 | microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2024-49042 | HIGH 7.2 | microsoft azure_database_for_postgresql_flexible_server Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2018-8554 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019. This CVE ID is unique from CVE-2018-8485, CV | 1.2% | — |
| CVE-2018-8462 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 | 1.2% | — |