56.707 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-26178 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-26173 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2026-26155 | MED 6.5 | microsoft windows_10_1607 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-53136 | MED 5.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authorized attacker to disclose information locally. | 0.9% | — |
| CVE-2022-44691 | HIGH 7.8 | microsoft 365_apps Microsoft Office OneNote Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2021-26427 | CRIT 9.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-29060 | MED 6.7 | microsoft visual_studio_2017 Visual Studio Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-43238 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-1392 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Delivery Optimization service improperly handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1388, CVE-2020-1394, CVE-2020-1395. | 0.9% | — |
| CVE-2024-43587 | MED 5.9 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-22710 | MED 5.5 | microsoft windows_10 Windows Common Log File System Driver Denial of Service Vulnerability | 0.9% | — |
| CVE-2024-43476 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.9% | — |
| CVE-2020-1080 | HIGH 8.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory. An attacker who successfully exploited these vulnerabilities could gain elevated privileges on a target operating system.</p> <p | 0.9% | — |
| CVE-2020-1047 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory. An attacker who successfully exploited these vulnerabilities could gain elevated privileges on a target operating system.</p> <p | 0.9% | — |
| CVE-2020-17076 | HIGH 7.8 | microsoft windows_10 Windows Update Orchestrator Service Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-1596 | MED 5.4 | microsoft windows_10 <p>A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfully exploited this vulnerability could obtain information to further compromise a users's encrypted transmission channel.</p> <p>To exploit | 0.9% | — |
| CVE-2020-1203 | HIGH 7.8 | microsoft visual_studio An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory, aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE | 0.9% | — |
| CVE-2020-1202 | HIGH 7.8 | microsoft visual_studio An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory, aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE | 0.9% | — |
| CVE-2024-28917 | MED 6.2 | microsoft azure_arc_extension_microsoft.azstackhci.operator Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-24106 | MED 5.5 | microsoft windows_10 Windows DirectX Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-24079 | MED 5.5 | microsoft windows_10 Windows Backup Engine Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-24076 | MED 5.5 | microsoft windows_10 Microsoft Windows VMSwitch Information Disclosure Vulnerability | 0.9% | — |
| CVE-2024-20694 | MED 5.5 | microsoft windows_10_1607 Windows CoreMessaging Information Disclosure Vulnerability | 0.9% | — |
| CVE-2023-21564 | HIGH 7.1 | microsoft azure_devops_server Azure DevOps Server Cross-Site Scripting Vulnerability | 0.9% | — |
| CVE-2026-65681 | HIGH 7.5 | microsoft windows_10_1607 Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network. | 0.9% | — |