56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-58726 | HIGH 7.5 | microsoft windows_10_1507 Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2020-1133 | MED 5.5 | microsoft visual_studio <p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exp | 1.0% | — |
| CVE-2023-21751 | MED 6.5 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 1.0% | — |
| CVE-2023-36590 | HIGH 7.3 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36583 | HIGH 7.3 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36582 | HIGH 7.3 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36578 | HIGH 7.3 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-35806 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2021-31169 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-31168 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-31165 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-15706 | MED 6.4 | canonical ubuntu_linux GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restri | 1.0% | — |
| CVE-2020-0804 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0778, CVE-2020 | 1.0% | — |
| CVE-2022-34301 | MED 6.7 | kidan cryptopro_securedisk_for_bitlocker A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replac | 1.0% | — |
| CVE-2020-17068 | HIGH 7.8 | microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2020-17037 | HIGH 7.8 | microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-16916 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when Windows improperly handles COM object creation. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges.</p> <p>To exploit this vulnerability, an attacker | 1.0% | — |
| CVE-2020-1549 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows CDP User Components improperly handle memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted app | 1.0% | — |
| CVE-2020-1486 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, | 1.0% | — |
| CVE-2026-64921 | HIGH 8.8 | microsoft sharepoint_server Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2017-8467 | HIGH 7.0 | microsoft windows_10 Graphics in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it han | 1.0% | — |
| CVE-2026-56190 | CRIT 9.8 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-56159 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-55010 | CRIT 9.8 | microsoft minecraft_bedrock_dedicated_server Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-50518 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 1.0% | — |