56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-0727 | HIGH 7.8 | microsoft visual_studio An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, a | 1.0% | — |
| CVE-2023-21695 | HIGH 7.5 | microsoft windows_10 Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2020-1143 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then | 1.0% | — |
| CVE-2025-64678 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-48814 | HIGH 7.5 | microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network. | 1.0% | — |
| CVE-2025-48799 | HIGH 7.8 | microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally. | 1.0% | — |
| CVE-2025-24992 | MED 5.5 | microsoft windows_10_1507 Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally. | 1.0% | — |
| CVE-2021-43237 | HIGH 7.8 | microsoft windows_10 Windows Setup Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2019-1413 | MED 4.3 | microsoft edge A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'. | 1.0% | — |
| CVE-2019-1272 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system, aka 'Wi | 1.0% | — |
| CVE-2013-1275 | HIGH 7.0 | microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently | 1.0% | — |
| CVE-2013-1265 | HIGH 7.0 | microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently | 1.0% | — |
| CVE-2013-1253 | HIGH 7.0 | microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently | 1.0% | — |
| CVE-2026-26121 | HIGH 7.5 | microsoft azure_iot_explorer Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network. | 1.0% | — |
| CVE-2020-17138 | MED 5.5 | microsoft windows_10 Windows Error Reporting Information Disclosure Vulnerability | 1.0% | — |
| CVE-2019-1169 | HIGH 7.8 | microsoft windows_7 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then | 1.0% | — |
| CVE-2025-29964 | HIGH 8.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-29963 | HIGH 8.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-30392 | CRIT 9.8 | microsoft azure_ai_bot_service Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2020-17011 | HIGH 7.8 | microsoft windows_10 Windows Port Class Library Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2024-43477 | HIGH 7.5 | microsoft entra_id Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant. | 1.0% | — |
| CVE-2020-0798 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system p | 1.0% | — |
| CVE-2019-0942 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists in the Unified Write Filter (UWF) feature for Windows 10 when it improperly restricts access to the registry, aka 'Unified Write Filter Elevation of Privilege Vulnerability'. | 1.0% | — |
| CVE-2005-3170 | MED 5.0 | microsoft windows_2000 The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they a | 1.0% | — |
| CVE-2026-61345 | MED 6.5 | microsoft windows_10_1607 Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. | 1.0% | — |