56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-26869 | MED 5.5 | microsoft windows_10 Windows ActiveX Installer Service Information Disclosure Vulnerability | 1.0% | — |
| CVE-2021-24107 | MED 5.5 | microsoft windows_10 Windows Event Tracing Information Disclosure Vulnerability | 1.0% | — |
| CVE-2024-30033 | HIGH 7.0 | microsoft windows_10_21h2 Windows Search Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-1122 | MED 5.5 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exploi | 1.0% | — |
| CVE-2026-56196 | HIGH 8.8 | microsoft windows_admin_center Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-49757 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2023-36029 | MED 4.3 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1.0% | — |
| CVE-2023-36702 | HIGH 7.8 | microsoft windows_10_1507 Microsoft DirectMusic Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-41088 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2020-16908 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in Windows Setup in the way it handles directories.</p> <p>A locally authenticated attacker could run arbitrary code with elevated system privileges. After successfully exploiting the vulnerability, an attacker | 1.0% | — |
| CVE-2020-1082 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfully exploited the vul | 1.0% | — |
| CVE-2026-47289 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-23655 | MED 6.5 | microsoft confidential_sidecar_containers Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2024-43596 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-35634 | HIGH 8.0 | microsoft windows_11_21h2 Windows Bluetooth Driver Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2026-62818 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-50432 | MED 5.3 | microsoft windows_10_1607 Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network. | 1.0% | — |
| CVE-2024-30053 | MED 6.5 | microsoft azure_migrate Azure Migrate Cross-Site Scripting Vulnerability | 1.0% | — |
| CVE-2023-24948 | HIGH 7.4 | microsoft windows_10_1507 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2025-26630 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 1.0% | — |
| CVE-2025-24057 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 1.0% | — |
| CVE-2024-38164 | CRIT 9.6 | microsoft groupme An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link. | 1.0% | — |
| CVE-2024-21341 | MED 6.8 | microsoft windows_10_1809 Windows Kernel Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2020-1369 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1344, CVE-2020-1362. | 1.0% | — |
| CVE-2020-1344 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1362, CVE-2020-1369. | 1.0% | — |