56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1268 | HIGH 7.8 | microsoft windows_10 An elevation of privilege exists when Winlogon does not properly handle file path information, aka 'Winlogon Elevation of Privilege Vulnerability'. | 1.0% | — |
| CVE-2017-8593 | HIGH 7.0 | microsoft windows_10 Microsoft Win32k in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to | 1.0% | — |
| CVE-2022-22026 | HIGH 8.8 | microsoft windows_10 Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2025-21352 | MED 6.5 | microsoft windows_10_1507 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 1.0% | — |
| CVE-2025-21254 | MED 6.5 | microsoft windows_10_1607 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 1.0% | — |
| CVE-2022-30214 | MED 6.6 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-33142 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Server Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-17092 | HIGH 7.8 | microsoft windows_10 Windows Network Connections Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2018-0842 | HIGH 7.0 | microsoft windows_10 Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow an elevation of privilege vulnerability due to how obj | 1.0% | — |
| CVE-2018-0828 | HIGH 7.8 | microsoft windows_10 Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password is stored, aka "Windows Elevation of Privilege Vulnerability". | 1.0% | — |
| CVE-2024-49117 | HIGH 8.8 | microsoft windows_11_22h2 Windows Hyper-V Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2024-30063 | MED 6.7 | microsoft windows_10_1507 Windows Distributed File System (DFS) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-38139 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-16885 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Storage VSP Driver improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.</p> <p>To exploit the vulnerability, an attacker | 1.0% | — |
| CVE-2020-0957 | HIGH 7.8 | microsoft windows_7 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0956, CVE-2020-0958. | 1.0% | — |
| CVE-2020-0877 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0788, CVE-2020-0887. | 1.0% | — |
| CVE-2022-21879 | MED 5.5 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2025-21216 | MED 6.5 | microsoft windows_10_1607 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 1.0% | — |
| CVE-2025-21212 | MED 6.5 | microsoft windows_10_1607 Internet Connection Sharing (ICS) Denial of Service Vulnerability | 1.0% | — |
| CVE-2025-21331 | HIGH 7.3 | microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2024-37968 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 1.0% | — |
| CVE-2023-33153 | MED 6.8 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2021-36950 | MED 5.4 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 1.0% | — |
| CVE-2021-36946 | MED 5.4 | microsoft dynamics_365_business_central Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | 1.0% | — |
| CVE-2020-1418 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Diagnostics Execution Service fails to properly sanitize input, leading to an unsecure library-loading behavior, aka 'Windows Diagnostics Hub Elevation of Privilege Vulnerability'. This CVE ID is | 1.0% | — |