56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-41066 | MED 4.4 | microsoft dynamics_365_business_central_2019 Microsoft Dynamics Business Central Information Disclosure Vulnerability | 1.1% | — |
| CVE-2021-28316 | MED 4.2 | microsoft windows_10 Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2024-43550 | HIGH 7.4 | microsoft windows_10_1507 Windows Secure Channel Spoofing Vulnerability | 1.1% | — |
| CVE-2022-21887 | HIGH 7.0 | microsoft windows_11 Win32k Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2019-1341 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when umpo.dll of the Power Service, improperly handles a Registry Restore Key function, aka 'Windows Power Service Elevation of Privilege Vulnerability'. | 1.1% | — |
| CVE-2023-38160 | MED 5.5 | microsoft windows_10_1507 Windows TCP/IP Information Disclosure Vulnerability | 1.1% | — |
| CVE-2022-41118 | HIGH 7.5 | microsoft windows_10 Windows Scripting Languages Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-38004 | HIGH 7.8 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2020-1115 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the <a href="https://technet.microsoft.com/library/security/dn848375.aspx#CLFS">Windows Common Log File System (CLFS)</a> driver improperly handles objects in memory. An attacker who successfully exploited | 1.1% | — |
| CVE-2022-41057 | HIGH 7.8 | microsoft windows_10 Windows HTTP.sys Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2022-21906 | MED 5.5 | microsoft windows_10 Windows Defender Application Control Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2025-53727 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2024-43574 | HIGH 8.3 | microsoft windows_10_21h2 Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-29334 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1.1% | — |
| CVE-2021-38672 | HIGH 8.0 | microsoft windows_11 Windows Hyper-V Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2025-29792 | HIGH 7.3 | microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 1.1% | — |
| CVE-2022-21918 | MED 6.5 | microsoft windows_10 DirectX Graphics Kernel File Denial of Service Vulnerability | 1.1% | — |
| CVE-2024-49132 | HIGH 8.1 | microsoft windows_10_1809 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2024-49123 | HIGH 8.1 | microsoft windows_10_1809 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2024-21329 | HIGH 7.3 | microsoft azure_connected_machine_agent Azure Connected Machine Agent Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2019-1414 | HIGH 7.8 | microsoft visual_studio_code An elevation of privilege vulnerability exists in Visual Studio Code when it exposes a debug listener to users of a local computer, aka 'Visual Studio Code Elevation of Privilege Vulnerability'. | 1.1% | — |
| CVE-2019-1320 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1322, CVE-2019-1340. | 1.1% | — |
| CVE-2026-20922 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 1.1% | — |
| CVE-2026-20854 | HIGH 7.5 | microsoft windows_11_24h2 Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2023-21740 | HIGH 7.8 | microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability | 1.1% | — |