56.712 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-25173 | HIGH 8.0 | microsoft windows_10_1607 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2022-35832 | MED 5.5 | microsoft windows_10 Windows Event Tracing Denial of Service Vulnerability | 0.9% | — |
| CVE-2019-1028 | HIGH 7.8 | microsoft windows_10 An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that coul | 0.9% | — |
| CVE-2019-1027 | HIGH 7.8 | microsoft windows_10 An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that coul | 0.9% | — |
| CVE-2019-1026 | HIGH 7.8 | microsoft windows_10 An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that coul | 0.9% | — |
| CVE-2019-1022 | HIGH 7.8 | microsoft windows_10 An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that coul | 0.9% | — |
| CVE-2019-1021 | HIGH 7.8 | microsoft windows_10 An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that coul | 0.9% | — |
| CVE-2024-38182 | CRIT 9.0 | microsoft dynamics_365 Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2024-30075 | HIGH 8.0 | microsoft windows_server_2008 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-21795 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2022-29121 | MED 6.5 | microsoft windows_10 Windows WLAN AutoConfig Service Denial of Service Vulnerability | 0.9% | — |
| CVE-2021-26434 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-30018 | HIGH 7.8 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-39804 | HIGH 7.1 | microsoft powerpoint A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to t | 0.9% | — |
| CVE-2023-33132 | MED 6.3 | microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability | 0.9% | — |
| CVE-2023-21721 | MED 6.5 | microsoft onenote Microsoft OneNote Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-36956 | MED 4.4 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-21202 | MED 6.1 | microsoft windows_10_1507 Windows Recovery Environment Agent Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-43479 | HIGH 8.5 | microsoft power_automate Microsoft Power Automate Desktop Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2020-16942 | MED 4.1 | microsoft sharepoint_enterprise_server <p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts | 0.9% | — |
| CVE-2024-38152 | HIGH 7.8 | microsoft windows_10_1507 Windows OLE Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2020-17088 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-37978 | HIGH 8.0 | microsoft windows_11_22h2 Secure Boot Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2023-29338 | MED 6.6 | microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability | 0.9% | — |
| CVE-2019-1162 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An att | 0.9% | — |