56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-27921 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | 1.2% | — |
| CVE-2026-26116 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1.2% | — |
| CVE-2026-23674 | HIGH 7.5 | microsoft windows_10_1607 Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | 1.2% | — |
| CVE-2020-1592 | MED 4.4 | microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.</p> <p>To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploite | 1.2% | — |
| CVE-2013-1342 | HIGH 7.8 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a | 1.2% | — |
| CVE-2025-30387 | CRIT 9.8 | microsoft azure_ai_document_intelligence_studio Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a network. | 1.2% | — |
| CVE-2023-41764 | MED 5.5 | microsoft 365_apps Microsoft Office Spoofing Vulnerability | 1.2% | — |
| CVE-2023-29345 | MED 6.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2023-21799 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2023-21798 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2023-21797 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2013-1279 | HIGH 7.2 | microsoft windows_7 Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges | 1.2% | — |
| CVE-2026-35424 | HIGH 7.5 | microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2024-20673 | HIGH 7.8 | microsoft excel Microsoft Office Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2023-35619 | MED 5.3 | microsoft office_long_term_servicing_channel Microsoft Outlook for Mac Spoofing Vulnerability | 1.2% | — |
| CVE-2022-34709 | MED 6.0 | microsoft windows_10 Windows Defender Credential Guard Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2018-8415 | HIGH 7.8 | microsoft powershell_core A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka "Microsoft PowerShell Tampering Vulnerability." This affects Windows 7, PowerShell Core 6.1, Windows Server 2012 R2, Windows RT 8.1, PowerShell Core 6.0, | 1.2% | — |
| CVE-2026-57092 | CRIT 9.9 | microsoft windows_10_1607 Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. | 1.2% | — |
| CVE-2023-24897 | HIGH 7.8 | microsoft .net .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2018-8549 | MED 5.5 | microsoft windows_10 A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 201 | 1.2% | — |
| CVE-2025-24061 | HIGH 7.8 | microsoft windows_10_1507 Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally. | 1.2% | — |
| CVE-2024-20692 | MED 5.7 | microsoft windows_10_1507 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | 1.2% | — |
| CVE-2020-1548 | HIGH 7.8 | microsoft windows_10 An information disclosure vulnerability exists when the Windows WaasMedic Service improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted appl | 1.2% | — |
| CVE-2019-1267 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Compatibility Appraiser where a configuration file, with local privileges, is vulnerable to symbolic link and hard link attacks, aka 'Microsoft Compatibility Appraiser Elevation of Privilege Vulnerabi | 1.2% | — |
| CVE-2024-30100 | HIGH 7.8 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 1.2% | — |