56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1029 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE | 1.0% | — |
| CVE-2020-0865 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0777, CVE-2020-0797, CVE-2020-08 | 1.0% | — |
| CVE-2020-0800 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0777, CVE-2020-0797, CVE-2020-08 | 1.0% | — |
| CVE-2020-0797 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0777, CVE-2020-0800, CVE-2020-08 | 1.0% | — |
| CVE-2023-36436 | HIGH 7.8 | microsoft windows_10_1507 Windows MSHTML Platform Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2021-38633 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2025-29801 | HIGH 7.8 | microsoft autoupdate Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | 1.0% | — |
| CVE-2025-29800 | HIGH 7.8 | microsoft autoupdate Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | 1.0% | — |
| CVE-2025-21395 | HIGH 7.8 | microsoft 365_apps Microsoft Access Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2024-49056 | HIGH 7.3 | microsoft airlift_microsoft_com Authentication bypass by assumed-immutable data on airlift.microsoft.com allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2023-36762 | HIGH 7.3 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-34719 | HIGH 7.8 | microsoft windows_10 Windows Distributed File System (DFS) Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2026-26122 | MED 6.5 | microsoft aci_confidential_containers Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2019-1041 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, | 1.0% | — |
| CVE-2026-48579 | CRIT 9.1 | microsoft exchange_online Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-21218 | HIGH 7.5 | microsoft .net Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network. | 1.0% | — |
| CVE-2024-29056 | MED 4.3 | microsoft windows_server_2008 Windows Authentication Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2019-1044 | MED 5.3 | microsoft windows_10 A security feature bypass vulnerability exists when Windows Secure Kernel Mode fails to properly handle objects in memory. To exploit the vulnerability, a locally-authenticated attacker could attempt to run a specially crafted application on a targeted system. | 1.0% | — |
| CVE-2023-38188 | MED 4.5 | microsoft azure_hdinsight Azure Apache Hadoop Spoofing Vulnerability | 1.0% | — |
| CVE-2021-31167 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-0843 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins | 1.0% | — |
| CVE-2020-0842 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins | 1.0% | — |
| CVE-1999-1104 | MED 4.6 | microsoft windows_95 Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords. | 1.0% | — |
| CVE-2023-21776 | MED 5.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 1.0% | — |
| CVE-2017-8577 | HIGH 7.0 | microsoft windows_10 Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to | 1.0% | — |