56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-38051 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-36027 | HIGH 7.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2025-53153 | MED 5.7 | microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2025-53148 | MED 5.7 | microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2025-53138 | MED 5.7 | microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2025-50157 | MED 5.7 | microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2024-26247 | MED 4.7 | microsoft edge Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2024-26177 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 1.1% | — |
| CVE-2020-16964 | HIGH 7.8 | microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2020-16963 | HIGH 7.8 | microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2020-16962 | HIGH 7.8 | microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2020-16959 | HIGH 7.8 | microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2020-16958 | HIGH 7.8 | microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2022-33674 | HIGH 8.3 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2025-55243 | HIGH 7.5 | microsoft officeplus Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network. | 1.1% | — |
| CVE-2023-35297 | HIGH 8.1 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2020-16943 | MED 6.5 | microsoft dynamics_365 <p>An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Commerce. An unauthenticated attacker who successfully exploited this vulnerability could update data without proper authorization.</p> <p>To exploit the vulnerability, an attacker wou | 1.1% | — |
| CVE-2026-20856 | HIGH 8.1 | microsoft windows_10_1607 Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | 1.1% | — |
| CVE-2024-26220 | MED 5.0 | microsoft windows_10_1507 Windows Mobile Hotspot Information Disclosure Vulnerability | 1.1% | — |
| CVE-2024-21394 | HIGH 7.6 | microsoft dynamics_365 Dynamics 365 Field Service Spoofing Vulnerability | 1.1% | — |
| CVE-2022-21969 | CRIT 9.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2020-0791 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0898. | 1.1% | — |
| CVE-2018-0788 | HIGH 7.0 | microsoft windows_7 The Windows Adobe Type Manager Font Driver (Atmfd.dll) in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 and R2 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka | 1.1% | — |
| CVE-2026-32093 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally. | 1.1% | — |
| CVE-2025-55698 | HIGH 7.7 | microsoft windows_11_24h2 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network. | 1.1% | — |