56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-35348 | MED 6.5 | microsoft windows_server_2016 Active Directory Federation Service Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2020-17126 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 1.0% | — |
| CVE-2023-36881 | MED 4.5 | microsoft azure_hdinsight Azure Apache Ambari Spoofing Vulnerability | 1.0% | — |
| CVE-2023-36877 | MED 4.5 | microsoft azure_hdinsight Azure Apache Oozie Spoofing Vulnerability | 1.0% | — |
| CVE-2020-0911 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when Windows Modules Installer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context.</p> <p>An attacker could exploit t | 1.0% | — |
| CVE-2013-3888 | HIGH 8.4 | microsoft windows_7 dxgkrnl.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel Subsystem Double Fetch Vulnerability." | 1.0% | — |
| CVE-2025-25002 | MED 6.8 | microsoft azure_local_cluster Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network. | 1.0% | — |
| CVE-2022-33635 | HIGH 7.8 | microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-21916 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-1308 | HIGH 7.0 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or de | 1.0% | — |
| CVE-2024-20684 | MED 6.5 | microsoft windows_11_21h2 Windows Hyper-V Denial of Service Vulnerability | 1.0% | — |
| CVE-2020-16895 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash. An attacker who successfully exploited this vulnerability could delete a targeted file leading to an elevated status.</p> <p>To exploit t | 1.0% | — |
| CVE-2020-0984 | HIGH 7.8 | microsoft autoupdate An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka 'Microsoft (MAU) Office Elevation of Privilege Vulnerability'. | 1.0% | — |
| CVE-2020-0861 | HIGH 7.8 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Network Driver Interface Specification (NDIS) improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Network Dri | 1.0% | — |
| CVE-2019-1190 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally au | 1.0% | — |
| CVE-2026-47302 | HIGH 7.5 | microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | 1.0% | — |
| CVE-2026-48573 | HIGH 7.9 | microsoft windows_10_1607 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 1.0% | — |
| CVE-2024-38220 | CRIT 9.0 | microsoft azure_stack_hub Azure Stack Hub Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2026-48576 | HIGH 7.9 | microsoft windows_10_1607 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 1.0% | — |
| CVE-2026-50470 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-50463 | HIGH 7.5 | microsoft windows_10_1809 Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-47633 | HIGH 7.5 | microsoft cost_management Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-32952 | MED 5.3 | microsoft go-ntlmssp go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using `ntlmssp.Negotiator` as an HTTP transport | 1.0% | — |
| CVE-2025-64676 | HIGH 7.2 | microsoft purview '.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network. | 1.0% | — |
| CVE-2023-36576 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 1.0% | — |