56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-8641 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows | 1.1% | — |
| CVE-2025-29969 | HIGH 7.5 | microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2024-38187 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2024-38185 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2024-30086 | HIGH 7.8 | microsoft windows_10_1507 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2023-35308 | MED 6.5 | microsoft windows_10_1507 Windows MSHTML Platform Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2020-17071 | MED 5.5 | microsoft windows_10 Windows Delivery Optimization Information Disclosure Vulnerability | 1.1% | — |
| CVE-2020-17069 | MED 5.5 | microsoft windows_10 Windows NDIS Information Disclosure Vulnerability | 1.1% | — |
| CVE-2023-21705 | HIGH 8.8 | microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2020-1070 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An | 1.1% | — |
| CVE-2026-62898 | HIGH 7.5 | microsoft .net Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2023-36710 | HIGH 7.8 | microsoft windows_10_1507 Windows Media Foundation Core Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-41120 | HIGH 7.8 | microsoft windows_sysmon Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2024-38262 | HIGH 7.5 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-33632 | MED 4.7 | microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2025-21366 | HIGH 7.8 | microsoft 365_apps Microsoft Access Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-41032 | HIGH 7.8 | fedoraproject fedora NuGet Client Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2025-21413 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2025-21411 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2025-21409 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2025-21339 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-36047 | HIGH 7.8 | microsoft windows_10_1809 Windows Authentication Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2026-56186 | HIGH 8.1 | microsoft windows_10_1607 Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2026-57108 | HIGH 7.5 | microsoft .net Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2018-0831 | HIGH 7.8 | microsoft windows_10 The Windows kernel in Windows 10 versions 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Kernel Elevation of Privilege Vulnerabilit | 1.1% | — |