56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-32722 | MED 5.5 | microsoft windows_10_1507 Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally. | 1.0% | — |
| CVE-2022-37964 | HIGH 7.8 | microsoft windows_7 Windows Kernel Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-17041 | HIGH 7.8 | microsoft windows_10 Windows Print Configuration Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-17024 | HIGH 7.8 | microsoft windows_10 Windows Client Side Rendering Print Provider Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-0779 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0798, CVE-2020-0814, CVE-2020-0842, CVE-2020-084 | 1.0% | — |
| CVE-2017-8581 | HIGH 7.0 | microsoft windows_10 Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to | 1.0% | — |
| CVE-2024-30048 | HIGH 7.6 | microsoft dynamics_365_customer_insights Dynamics 365 Customer Insights Spoofing Vulnerability | 1.0% | — |
| CVE-2024-30047 | HIGH 7.6 | microsoft dynamics_365_customer_insights Dynamics 365 Customer Insights Spoofing Vulnerability | 1.0% | — |
| CVE-2025-49681 | MED 6.5 | microsoft windows_server_2008 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2025-49671 | MED 6.5 | microsoft windows_server_2008 Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2020-16853 | HIGH 7.1 | microsoft onedrive <p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status.</p> <p>To | 1.0% | — |
| CVE-2024-49103 | MED 4.3 | microsoft windows_10_1809 Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | 1.0% | — |
| CVE-2024-49099 | MED 4.3 | microsoft windows_10_1809 Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | 1.0% | — |
| CVE-2024-49098 | MED 4.3 | microsoft windows_10_1809 Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability | 1.0% | — |
| CVE-2026-33844 | CRIT 9.0 | microsoft azure_managed_instance_for_apache_cassandra Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. | 1.0% | — |
| CVE-2024-21330 | HIGH 7.8 | microsoft azure_automation Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2026-47295 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2026-45495 | HIGH 8.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36593 | HIGH 7.8 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-21796 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2023-21775 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-26935 | MED 6.5 | microsoft windows_10 Windows WLAN AutoConfig Service Information Disclosure Vulnerability | 1.0% | — |
| CVE-2021-42301 | LOW 3.3 | microsoft azure_rtos Azure RTOS Information Disclosure Vulnerability | 1.0% | — |
| CVE-2020-17099 | MED 6.8 | microsoft windows_10 Windows Lock Screen Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2026-34401 | MED 6.5 | microsoft xml_notepad XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, XML Notepad does not disable DTD processing by default which means external entities are resolved automatically. | 1.0% | — |