56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-21792 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-21784 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-21782 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-21780 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2021-1657 | HIGH 7.8 | microsoft windows_10 Windows Fax Compose Form Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2019-1285 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1256. | 0.9% | — |
| CVE-2019-1271 | HIGH 7.8 | microsoft windows_10 An elevation of privilege exists in hdAudio.sys which may lead to an out of band write, aka 'Windows Media Elevation of Privilege Vulnerability'. | 0.9% | — |
| CVE-2019-1269 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system, aka 'Wi | 0.9% | — |
| CVE-2026-50649 | HIGH 7.8 | microsoft .net Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. | 0.9% | — |
| CVE-2024-43495 | HIGH 7.3 | microsoft windows_11_22h2 Windows libarchive Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-36410 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.9% | — |
| CVE-2023-36031 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.9% | — |
| CVE-2023-36562 | HIGH 7.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-0860 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows ActiveX Installer Service Eleva | 0.9% | — |
| CVE-2019-1420 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the dssvc.dll handles file creation allowing for a file overwrite or creation in a secured location, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1422, CV | 0.9% | — |
| CVE-2026-48560 | MED 5.4 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2024-43463 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-32033 | MED 6.6 | microsoft windows_server_2008 Microsoft Failover Cluster Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2021-34509 | MED 5.5 | microsoft windows_10 Storage Spaces Controller Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-25000 | HIGH 8.8 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2025-21365 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2025-21362 | HIGH 8.4 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-49093 | HIGH 8.8 | microsoft windows_11_24h2 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2022-34686 | MED 5.5 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Information Disclosure Vulnerability | 0.9% | — |
| CVE-2022-34685 | MED 5.5 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Information Disclosure Vulnerability | 0.9% | — |