56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36558 | MED 6.2 | microsoft .net ASP.NET Core Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2022-34302 | MED 6.7 | horizondatasys uefi_bootloader A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace | 1.1% | — |
| CVE-2018-8455 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windo | 1.1% | — |
| CVE-2018-8232 | HIGH 7.8 | microsoft visual_studio_2017 A Tampering vulnerability exists when Microsoft Macro Assembler improperly validates code, aka "Microsoft Macro Assembler Tampering Vulnerability." This affects Microsoft Visual Studio. | 1.1% | — |
| CVE-2026-54130 | CRIT 9.8 | microsoft 365_copilot Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2023-21548 | HIGH 8.1 | microsoft windows_10_1607 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-21535 | HIGH 8.1 | microsoft windows_10_1607 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2021-26889 | HIGH 7.8 | microsoft windows_10 Windows Update Stack Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2019-0892 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. | 1.1% | — |
| CVE-2019-0766 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege | 1.1% | — |
| CVE-2019-0696 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. | 1.1% | — |
| CVE-2018-8441 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists due to an integer overflow in Windows Subsystem for Linux, aka "Windows Subsystem for Linux Elevation of Privilege Vulnerability." This affects Windows 10, Windows 10 Servers. | 1.1% | — |
| CVE-2017-8466 | HIGH 7.8 | microsoft windows_10 Windows Cursor in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows improper elevation of privilege, aka "Windows Cursor Elevation of Privilege Vulnerability". | 1.1% | — |
| CVE-2024-49071 | MED 6.5 | microsoft defender_for_endpoint Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2025-62456 | HIGH 8.8 | microsoft windows_11_23h2 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2025-26687 | HIGH 7.5 | microsoft 365_copilot Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2025-21393 | MED 6.3 | microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability | 1.1% | — |
| CVE-2021-43221 | MED 4.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2021-34483 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2026-54108 | MED 6.5 | microsoft sharepoint_server External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 1.1% | — |
| CVE-2025-53767 | CRIT 10.0 | microsoft azure_openai Azure OpenAI Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2024-49120 | HIGH 8.1 | microsoft windows_server_2012 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-23266 | HIGH 7.8 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2020-1250 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit thi | 1.1% | — |
| CVE-2020-1119 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when StartTileData.dll improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit this vul | 1.1% | — |