56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-49079 | HIGH 7.8 | microsoft windows_10_1507 Input Method Editor (IME) Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-30096 | MED 5.5 | microsoft windows_10_1809 Windows Cryptographic Services Information Disclosure Vulnerability | 0.9% | — |
| CVE-2020-17101 | HIGH 7.8 | microsoft heif_image_extension HEIF Image Extensions Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2026-55034 | HIGH 7.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2026-55021 | HIGH 7.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2020-1269 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, | 0.9% | — |
| CVE-2024-35248 | HIGH 7.3 | microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2023-36727 | MED 6.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.9% | — |
| CVE-2020-16891 | HIGH 8.8 | microsoft windows_10 <p>A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application o | 0.9% | — |
| CVE-2021-26441 | HIGH 7.8 | microsoft windows_10 Storage Spaces Controller Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2019-1164 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, | 0.9% | — |
| CVE-2026-62702 | MED 6.8 | microsoft windows_10_21h2 Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network. | 0.9% | — |
| CVE-2024-26203 | HIGH 7.3 | microsoft azure_data_studio Azure Data Studio Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2017-8562 | HIGH 7.0 | microsoft windows_10 Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Windows improperly handling calls to Advanced Local Procedure Call (ALPC) | 0.9% | — |
| CVE-2013-1278 | HIGH 7.4 | microsoft windows_7 Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges | 0.9% | — |
| CVE-2025-21415 | CRIT 9.9 | microsoft azure_ai_face_service Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2025-21354 | HIGH 8.4 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2020-16902 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.</p> <p>A locally authenticated attacker could run arbitrary code with elevat | 0.9% | — |
| CVE-2026-58277 | HIGH 8.8 | microsoft sharepoint_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2026-55052 | HIGH 8.8 | microsoft sharepoint_server Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2024-38204 | HIGH 7.5 | microsoft azure_functions Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2021-34510 | HIGH 7.8 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2026-47299 | HIGH 7.2 | microsoft azure_monitor_agent Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2026-50663 | HIGH 8.8 | microsoft age_of_empires_ii Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2024-30001 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0.9% | — |