56.713 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.472 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-0644 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Microsoft Windows implements predictable memory section names, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0635. | 0.9% | — |
| CVE-2019-1437 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1407, CVE-2019-1433, CVE-2019-14 | 0.9% | — |
| CVE-2019-1435 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1407, CVE-2019-1433, CVE-2019-14 | 0.9% | — |
| CVE-2019-1407 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1433, CVE-2019-1435, CVE-2019-14 | 0.9% | — |
| CVE-2026-62782 | MED 6.5 | microsoft windows_10_1607 Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-40400 | HIGH 8.0 | microsoft windows_10_1607 Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-40374 | MED 6.5 | microsoft power_automate_for_desktop Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2024-30012 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2025-21226 | MED 6.6 | microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-49078 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-49077 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-49073 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2023-36561 | HIGH 7.3 | microsoft azure_devops_server Azure DevOps Server Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-42299 | MED 5.6 | microsoft surface_pro_3_firmware Microsoft Surface Pro 3 Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2023-36696 | HIGH 7.8 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-1411 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1336. | 0.9% | — |
| CVE-2020-1406 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Network List Service handles objects in memory, aka 'Windows Network List Service Elevation of Privilege Vulnerability'. | 0.9% | — |
| CVE-2020-0702 | MED 6.8 | microsoft surface_hub_firmware A security feature bypass vulnerability exists in Surface Hub when prompting for credentials, aka 'Surface Hub Security Feature Bypass Vulnerability'. | 0.9% | — |
| CVE-2026-55008 | CRIT 9.6 | microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2026-48561 | CRIT 9.6 | microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2023-36878 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2022-38019 | HIGH 7.8 | microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-38010 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2021-38634 | HIGH 7.1 | microsoft windows_10 Microsoft Windows Update Client Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-0789 | HIGH 7.1 | microsoft visual_studio_2019 A denial of service vulnerability exists when the Visual Studio Extension Installer Service improperly handles hard links, aka 'Visual Studio Extension Installer Service Denial of Service Vulnerability'. | 0.9% | — |