IT
56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-25185 MED 5.3 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attacker to perform spoofing over a network. 1.0%
CVE-2026-20849 HIGH 7.5 microsoft windows_10_1607 Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network. 1.0%
CVE-2024-43496 MED 6.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.0%
CVE-2017-8702 HIGH 7.0 microsoft windows_10 Windows Error Reporting (WER) in Microsoft Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows an attacker to gain greater access to sensitive information and system functionality, due to the way that WER handles and executes files, aka "Windows El 1.0%
CVE-2022-41044 HIGH 8.1 microsoft windows_7 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability 1.0%
CVE-2021-31170 HIGH 7.8 microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability 1.0%
CVE-2023-38147 HIGH 8.8 microsoft windows_10_1507 Windows Miracast Wireless Display Remote Code Execution Vulnerability 1.0%
CVE-2022-38038 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 1.0%
CVE-2026-56170 HIGH 7.5 microsoft .net Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. 1.0%
CVE-2025-62567 MED 5.3 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network. 1.0%
CVE-2024-38048 MED 6.5 microsoft windows_10_1507 Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability 1.0%
CVE-2024-38027 MED 6.5 microsoft windows_10_1507 Windows Line Printer Daemon Service Denial of Service Vulnerability 1.0%
CVE-2021-1704 HIGH 7.3 microsoft windows_10 Windows Hyper-V Elevation of Privilege Vulnerability 1.0%
CVE-2025-29956 MED 5.4 microsoft windows_10_1507 Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network. 1.0%
CVE-2020-1530 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows Remote Access improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application 1.0%
CVE-2020-0803 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0778, CVE-2020 1.0%
CVE-2020-0802 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0778, CVE-2020 1.0%
CVE-2024-30095 HIGH 7.8 microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 1.0%
CVE-2024-30062 HIGH 7.8 microsoft windows_server_2012 Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability 1.0%
CVE-2020-16905 MED 6.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it.</p> <p>An attacker who successfully exploit 1.0%
CVE-2020-0934 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows WpcDesktopMonSvc improperly manages memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. T 1.0%
CVE-2019-1477 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while loading printer drivers, aka 'Windows Printer Service Elevation of Privilege Vulnerability'. 1.0%
CVE-2017-8552 HIGH 7.8 microsoft windows_7 A kernel-mode driver in Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows 8 allows an elevation of privilege when it fails to properly handle objects in memory, 1.0%
CVE-2020-16935 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when Windows improperly handles COM object creation. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges.</p> <p>To exploit this vulnerability, an attacker 1.0%
CVE-2020-1522 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Speech Runtime improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted applica 1.0%