56.707 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-29326 | HIGH 7.8 | microsoft .net_framework .NET Framework Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-21921 | MED 4.4 | microsoft windows_10 Windows Defender Credential Guard Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2020-17073 | HIGH 7.8 | microsoft windows_10 Windows Update Orchestrator Service Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-1243 | HIGH 7.8 | microsoft windows_10 <p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.</p> <p>To exploit the vulnerability, an attacker who already has a privileged accoun | 0.9% | — |
| CVE-2020-16980 | HIGH 7.8 | microsoft windows_server_2012 <p>An elevation of privilege vulnerability exists when the Windows iSCSI Target Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.</p> <p>To exploit the vulnerability, an attack | 0.9% | — |
| CVE-2020-16936 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specia | 0.9% | — |
| CVE-2026-20824 | MED 5.5 | microsoft windows_10_1607 Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally. | 0.9% | — |
| CVE-2025-47998 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2024-41138 | HIGH 7.1 | microsoft teams A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypas | 0.9% | — |
| CVE-2024-30073 | HIGH 7.8 | microsoft windows_10_1507 Windows Security Zone Mapping Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2020-1253 | MED 6.7 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1251, | 0.9% | — |
| CVE-2023-28232 | HIGH 7.5 | microsoft windows_10_1507 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-41103 | MED 5.5 | microsoft 365_apps Microsoft Word Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-38657 | MED 6.1 | microsoft 365_apps Microsoft Office Graphics Component Information Disclosure Vulnerability | 0.9% | — |
| CVE-2020-16941 | MED 4.1 | microsoft sharepoint_enterprise_server <p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts | 0.9% | — |
| CVE-2020-0730 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'. | 0.9% | — |
| CVE-2025-21379 | HIGH 7.1 | microsoft windows_11_24h2 DHCP Client Service Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-38172 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-30144 | HIGH 7.5 | microsoft windows_10 Windows Bluetooth Service Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2021-26425 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2019-1270 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack, aka 'Microsoft Windows Store Installer Elevation of Privilege Vulnerability'. | 0.9% | — |
| CVE-2013-1292 | HIGH 7.4 | microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted applicat | 0.9% | — |
| CVE-2025-53720 | HIGH 8.0 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2019-1161 | HIGH 7.1 | microsoft forefront_endpoint_protection_2010 An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted c | 0.9% | — |
| CVE-2024-30004 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0.9% | — |