56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-49759 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2023-24893 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-21699 | MED 5.3 | microsoft windows_10 Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability | 1.1% | — |
| CVE-2023-21679 | HIGH 8.1 | microsoft windows_10_1607 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-21555 | HIGH 8.1 | microsoft windows_10_1607 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-21546 | HIGH 8.1 | microsoft windows_10_1607 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2026-21256 | HIGH 8.8 | microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network. | 1.1% | — |
| CVE-2026-44815 | CRIT 9.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. | 1.1% | — |
| CVE-2022-24511 | MED 5.5 | microsoft 365_apps Microsoft Office Word Tampering Vulnerability | 1.1% | — |
| CVE-2019-1167 | MED 4.1 | microsoft powershell_core A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'. | 1.1% | — |
| CVE-2026-50515 | CRIT 9.9 | microsoft azure_service_bus Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2025-49735 | HIGH 8.1 | microsoft windows_server_2012 Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network. | 1.1% | — |
| CVE-2023-21783 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2019-1278 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1253, CVE-2019-1303. | 1.1% | — |
| CVE-2024-49115 | HIGH 8.1 | microsoft windows_server_2016 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2024-43480 | MED 6.6 | microsoft azure_service_fabric Azure Service Fabric for Linux Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2020-1030 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. | 1.1% | — |
| CVE-2024-43482 | MED 6.5 | microsoft outlook Microsoft Outlook for iOS Information Disclosure Vulnerability | 1.1% | — |
| CVE-2017-0193 | HIGH 7.8 | microsoft windows_10 Windows Hyper-V in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to gain elevated privileges on a target | 1.1% | — |
| CVE-2023-36024 | HIGH 7.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2019-1185 | HIGH 7.3 | microsoft windows_10 An elevation of privilege vulnerability exists due to a stack corruption in Windows Subsystem for Linux. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticate | 1.1% | — |
| CVE-2026-26115 | HIGH 8.8 | microsoft sql_server_2016 Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2025-47966 | CRIT 9.8 | microsoft power_automate_for_desktop Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2024-43604 | MED 5.7 | microsoft outlook Outlook for Android Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2023-21717 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Elevation of Privilege Vulnerability | 1.1% | — |