IT
56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-21781 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0.9%
CVE-2021-36928 MED 6.0 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 0.9%
CVE-2022-21901 CRIT 9.0 microsoft windows_10 Windows Hyper-V Elevation of Privilege Vulnerability 0.9%
CVE-2021-1685 HIGH 7.3 microsoft windows_10 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability 0.9%
CVE-2026-20927 MED 5.3 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network. 0.9%
CVE-2025-49758 HIGH 8.8 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 0.9%
CVE-2022-21855 CRIT 9.0 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 0.9%
CVE-2021-42280 MED 5.5 microsoft windows_10 Windows Feedback Hub Elevation of Privilege Vulnerability 0.9%
CVE-2020-16976 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specia 0.9%
CVE-2024-26232 HIGH 7.3 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 0.9%
CVE-2023-21568 HIGH 7.3 microsoft sql_server_2019_integration_services Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vulnerability 0.9%
CVE-2019-1314 MED 6.8 microsoft windows_10_mobile A security feature bypass vulnerability exists in Windows 10 Mobile when Cortana allows a user to access files and folders through the locked screen, aka 'Windows 10 Mobile Security Feature Bypass Vulnerability'. 0.9%
CVE-2016-3258 MED 4.7 microsoft windows_10 Race condition in the kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Low Integrity protection mechanism and write to files by leveraging unspecified object-manager 0.9%
CVE-2024-38176 HIGH 8.1 microsoft groupme An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network. 0.9%
CVE-2024-38017 MED 5.5 microsoft windows_10_1507 Microsoft Message Queuing Information Disclosure Vulnerability 0.9%
CVE-2022-24455 HIGH 7.8 microsoft windows_10 Windows CD-ROM Driver Elevation of Privilege Vulnerability 0.9%
CVE-2020-1598 MED 6.1 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. 0.9%
CVE-2024-38219 MED 6.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 0.9%
CVE-2024-26167 MED 4.3 microsoft edge Microsoft Edge for Android Spoofing Vulnerability 0.9%
CVE-2023-24903 HIGH 8.1 microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 0.9%
CVE-2021-1729 HIGH 7.1 microsoft windows_10 Windows Update Stack Setup Elevation of Privilege Vulnerability 0.9%
CVE-2025-21387 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0.9%
CVE-2024-20659 HIGH 7.1 microsoft windows_10_1809 Windows Hyper-V Security Feature Bypass Vulnerability 0.9%
CVE-2024-38216 HIGH 8.2 microsoft azure_stack_hub Azure Stack Hub Elevation of Privilege Vulnerability 0.9%
CVE-2020-16876 HIGH 7.1 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.</p> <p>To exploit the 0.9%