IT
56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-36574 HIGH 7.3 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%
CVE-2023-36573 HIGH 7.3 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%
CVE-2023-36572 HIGH 7.3 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%
CVE-2023-36571 HIGH 7.3 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%
CVE-2023-36570 HIGH 7.3 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%
CVE-2020-16851 HIGH 7.1 microsoft onedrive <p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status.</p> <p>To 1.0%
CVE-2019-1336 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges, aka 'Microsoft Windows Update Client Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1323. 1.0%
CVE-2019-1321 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows CloudStore improperly handles file Discretionary Access Control List (DACL), aka 'Microsoft Windows CloudStore Elevation of Privilege Vulnerability'. 1.0%
CVE-2019-1319 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. 1.0%
CVE-2019-1168 HIGH 7.8 microsoft windows_10 An elevation of privilege exists in the p2pimsvc service where an attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit this vulnerability, an attacker would first have to log on to the system. An a 1.0%
CVE-2017-8574 HIGH 7.0 microsoft windows_10 Graphics in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Microsoft Graphics Component Elevation of Privilege Vulnerability". This CVE ID is uniq 1.0%
CVE-2025-49677 HIGH 7.0 microsoft windows_11_22h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 1.0%
CVE-2020-0695 MED 5.4 microsoft office_online_server A spoofing vulnerability exists when Office Online Server does not validate origin in cross-origin communications correctly, aka 'Microsoft Office Online Server Spoofing Vulnerability'. 1.0%
CVE-2025-59284 LOW 3.3 microsoft windows_11_22h2 Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally. 1.0%
CVE-2023-36598 HIGH 7.8 microsoft windows_10_1507 Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability 1.0%
CVE-2023-36908 MED 6.5 microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability 1.0%
CVE-2023-24935 MED 6.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 1.0%
CVE-2022-21995 HIGH 7.9 microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability 1.0%
CVE-2021-26899 HIGH 7.8 microsoft windows_10 Windows UPnP Device Host Elevation of Privilege Vulnerability 1.0%
CVE-2020-0648 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows RSoP Service Application improperly handles memory.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a speci 1.0%
CVE-2026-47301 HIGH 8.8 microsoft configuration_manager_2503 Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. 1.0%
CVE-2024-21385 HIGH 8.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.0%
CVE-2022-24499 HIGH 7.8 microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability 1.0%
CVE-2020-17077 HIGH 7.8 microsoft windows_10 Windows Update Stack Elevation of Privilege Vulnerability 1.0%
CVE-2020-1079 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code. An attacker could then install programs; view, change, or delete dat 1.0%