56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-36930 | MED 5.3 | microsoft edge Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2025-21404 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1.1% | — |
| CVE-2023-23374 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2021-26865 | HIGH 8.8 | microsoft windows_10 Windows Container Execution Agent Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2021-31954 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2026-26154 | HIGH 7.5 | microsoft windows_server_2012 Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network. | 1.1% | — |
| CVE-2013-1294 | HIGH 7.0 | microsoft windows_7 Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges | 1.1% | — |
| CVE-2024-49090 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2018-8566 | MED 4.6 | microsoft windows_10 A security feature bypass vulnerability exists when Windows improperly suspends BitLocker Device Encryption, aka "BitLocker Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers. | 1.1% | — |
| CVE-2024-26240 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2020-1123 | MED 5.5 | microsoft windows_10 A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations. An attacker who successfully exploited this vulnerability could cause a system to stop responding. To exploit the vulnerability, | 1.1% | — |
| CVE-2020-1084 | MED 5.5 | microsoft windows_10 A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values. An attacker who successfully exploited this vulnerability could deny dependent security feature functionality. To exploit | 1.1% | — |
| CVE-2020-1076 | MED 5.5 | microsoft windows_10 A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on | 1.1% | — |
| CVE-2026-20967 | HIGH 8.8 | microsoft system_center_operations_manager Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2022-21846 | CRIT 9.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2026-32071 | HIGH 7.5 | microsoft windows_10_1607 Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2022-21897 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2024-49065 | MED 5.5 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-24895 | HIGH 7.8 | microsoft .net .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2021-42296 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2026-62901 | HIGH 7.5 | microsoft .net Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2023-21800 | HIGH 7.8 | microsoft windows_server_2008 Windows Installer Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2021-1725 | MED 5.5 | microsoft bot_framework_software_development_kit Bot Framework SDK Information Disclosure Vulnerability | 1.1% | — |
| CVE-2020-0983 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Delivery Optimization service improperly handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0934, CVE-2020-1009, CVE-2020-1011, CVE- | 1.1% | — |
| CVE-2025-59245 | CRIT 9.8 | microsoft sharepoint_online Microsoft SharePoint Online Elevation of Privilege Vulnerability | 1.1% | — |