56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-0858 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the "Public Account Pictures" folder improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privil | 0.9% | — |
| CVE-2026-40379 | CRIT 9.3 | microsoft entra_id Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2022-35822 | HIGH 7.1 | microsoft windows_10 Windows Defender Credential Guard Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2021-36967 | HIGH 8.0 | microsoft windows_10 Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2026-32173 | HIGH 8.6 | microsoft azure_sre_agent Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2025-49752 | CRIT 10.0 | microsoft azure_bastion_developer Azure Bastion Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2025-58717 | MED 6.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2025-55700 | MED 6.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2020-16892 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>To exploit the vulnerability, a | 0.9% | — |
| CVE-2019-1018 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delet | 0.9% | — |
| CVE-2019-1017 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install pr | 0.9% | — |
| CVE-2019-1014 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install pr | 0.9% | — |
| CVE-2019-0984 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vuln | 0.9% | — |
| CVE-2019-0960 | HIGH 7.0 | microsoft windows_7 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install pr | 0.9% | — |
| CVE-2025-29802 | HIGH 7.3 | microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | 0.9% | — |
| CVE-2022-21908 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-16975 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specia | 0.9% | — |
| CVE-2020-16974 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specia | 0.9% | — |
| CVE-2020-16972 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specia | 0.9% | — |
| CVE-2020-16912 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specia | 0.9% | — |
| CVE-2026-34348 | MED 6.5 | microsoft windows_10_1809 Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2020-1310 | MED 6.7 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1251, | 0.9% | — |
| CVE-2020-1258 | MED 6.7 | microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. | 0.9% | — |
| CVE-2024-30094 | HIGH 7.8 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-36409 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 0.9% | — |