56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-21781 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2021-36928 | MED 6.0 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2022-21901 | CRIT 9.0 | microsoft windows_10 Windows Hyper-V Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-1685 | HIGH 7.3 | microsoft windows_10 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2026-20927 | MED 5.3 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network. | 0.9% | — |
| CVE-2025-49758 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2022-21855 | CRIT 9.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2021-42280 | MED 5.5 | microsoft windows_10 Windows Feedback Hub Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-16976 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specia | 0.9% | — |
| CVE-2024-26232 | HIGH 7.3 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-21568 | HIGH 7.3 | microsoft sql_server_2019_integration_services Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2019-1314 | MED 6.8 | microsoft windows_10_mobile A security feature bypass vulnerability exists in Windows 10 Mobile when Cortana allows a user to access files and folders through the locked screen, aka 'Windows 10 Mobile Security Feature Bypass Vulnerability'. | 0.9% | — |
| CVE-2016-3258 | MED 4.7 | microsoft windows_10 Race condition in the kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Low Integrity protection mechanism and write to files by leveraging unspecified object-manager | 0.9% | — |
| CVE-2024-38176 | HIGH 8.1 | microsoft groupme An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2024-38017 | MED 5.5 | microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability | 0.9% | — |
| CVE-2022-24455 | HIGH 7.8 | microsoft windows_10 Windows CD-ROM Driver Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-1598 | MED 6.1 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. | 0.9% | — |
| CVE-2024-38219 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-26167 | MED 4.3 | microsoft edge Microsoft Edge for Android Spoofing Vulnerability | 0.9% | — |
| CVE-2023-24903 | HIGH 8.1 | microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2021-1729 | HIGH 7.1 | microsoft windows_10 Windows Update Stack Setup Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2025-21387 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-20659 | HIGH 7.1 | microsoft windows_10_1809 Windows Hyper-V Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2024-38216 | HIGH 8.2 | microsoft azure_stack_hub Azure Stack Hub Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-16876 | HIGH 7.1 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.</p> <p>To exploit the | 0.9% | — |