56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-38033 | HIGH 7.3 | microsoft windows_10_1507 PowerShell Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2024-37970 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2023-36785 | HIGH 7.8 | microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2021-26887 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file server is co-located with Terminal server, an attacker who successfully exploited the vulnerability woul | 1.1% | — |
| CVE-2024-43601 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code for Linux Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-35821 | MED 4.4 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 1.1% | — |
| CVE-2022-22049 | HIGH 7.8 | microsoft windows_10 Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2021-40440 | MED 5.4 | microsoft dynamics_365_business_central Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | 1.1% | — |
| CVE-2020-0731 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0691, CVE-2020-0719, CVE-2020-0720, CVE-2020- | 1.1% | — |
| CVE-2020-0635 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0644. | 1.1% | — |
| CVE-2019-0973 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could run arbitrary code with elevated system | 1.1% | — |
| CVE-2025-62473 | MED 6.5 | microsoft windows_10_1607 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2024-38190 | HIGH 8.6 | microsoft power_platform Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector. | 1.1% | — |
| CVE-2022-41039 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2020-1131 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit | 1.1% | — |
| CVE-2021-36961 | MED 5.5 | microsoft windows_10 Windows Installer Denial of Service Vulnerability | 1.1% | — |
| CVE-2025-62821 | CRIT 9.1 | microsoft heif_image_extension Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. This causes a caller to make a 1-byte allocation. Later, CopyPixels computes copy_size = str | 1.1% | — |
| CVE-2023-35387 | HIGH 8.8 | microsoft windows_10_1507 Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2024-49142 | HIGH 7.8 | microsoft 365_apps Microsoft Access Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-41121 | HIGH 7.8 | microsoft powershell Windows Graphics Component Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2021-41333 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2025-59254 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 1.0% | — |
| CVE-2021-34513 | HIGH 7.8 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-34512 | HIGH 7.8 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-34498 | HIGH 7.8 | microsoft windows_10 Windows GDI Elevation of Privilege Vulnerability | 1.0% | — |