56.712 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-28238 | HIGH 7.5 | microsoft windows_10_1507 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-35779 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2021-41375 | MED 4.4 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 0.9% | — |
| CVE-2026-58523 | MED 6.5 | microsoft edge_chromium Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network. | 0.9% | — |
| CVE-2026-57993 | HIGH 7.4 | microsoft edge_chromium Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2026-45489 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.9% | — |
| CVE-2024-49110 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-0898 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0791. | 0.9% | — |
| CVE-2020-0849 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Windows Hard Link Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0840, CVE-2020-0841, CVE-2020-0896. | 0.9% | — |
| CVE-2020-0841 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Windows Hard Link Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0840, CVE-2020-0849, CVE-2020-0896. | 0.9% | — |
| CVE-2020-0840 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Windows Hard Link Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0841, CVE-2020-0849, CVE-2020-0896. | 0.9% | — |
| CVE-2020-0834 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system, aka 'Wi | 0.9% | — |
| CVE-2020-0819 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Device Setup Manager improperly handles file operations, aka 'Windows Device Setup Manager Elevation of Privilege Vulnerability'. | 0.9% | — |
| CVE-2019-1433 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1407, CVE-2019-1435, CVE-2019-14 | 0.9% | — |
| CVE-2023-35624 | HIGH 7.3 | microsoft azure_connected_machine_agent Azure Connected Machine Agent Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2023-36886 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.9% | — |
| CVE-2020-1276 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, | 0.9% | — |
| CVE-2026-47282 | MED 6.5 | microsoft visual_studio_code Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-57987 | MED 6.5 | microsoft edge_chromium Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2024-38245 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming Service Driver Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-16973 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specia | 0.9% | — |
| CVE-2020-16909 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it.</p> <p>An attacker who successfully exploit | 0.9% | — |
| CVE-2025-24043 | HIGH 7.5 | microsoft windbg Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2023-28301 | LOW 3.7 | microsoft edge Microsoft Edge (Chromium-based) Tampering Vulnerability | 0.9% | — |
| CVE-2023-21766 | MED 4.7 | microsoft windows_10 Windows Overlay Filter Information Disclosure Vulnerability | 0.9% | — |