56.721 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.472 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-62837 | MED 6.5 | microsoft sharepoint_server Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-41109 | HIGH 8.8 | microsoft visual_studio_code Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network. | 0.9% | — |
| CVE-2024-49032 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-35270 | MED 5.3 | microsoft windows_10_1507 Windows iSCSI Service Denial of Service Vulnerability | 0.9% | — |
| CVE-2026-50415 | MED 5.3 | microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2024-38261 | HIGH 7.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-38066 | HIGH 7.8 | microsoft windows_10_1507 Windows Win32k Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2023-37139 | MED 5.5 | microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a stack overflow vulnerability via the function Js::ScopeSlots::IsDebuggerScopeSlotArray(). | 0.9% | — |
| CVE-2021-31970 | MED 5.5 | microsoft windows_10 Windows TCP/IP Driver Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2025-33054 | HIGH 8.1 | microsoft windows_11_22h2 Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2024-49109 | MED 6.6 | microsoft windows_10_1809 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-49101 | MED 6.6 | microsoft windows_10_1809 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2023-38164 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.9% | — |
| CVE-2021-26891 | HIGH 7.8 | microsoft windows_10 Windows Container Execution Agent Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-26875 | HIGH 7.8 | microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-38177 | HIGH 7.8 | microsoft app_installer Windows App Installer Spoofing Vulnerability | 0.9% | — |
| CVE-2024-21406 | HIGH 7.5 | microsoft windows_10_1607 Windows Printing Service Spoofing Vulnerability | 0.9% | — |
| CVE-2020-1587 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Ancillary Function Driver for WinSock improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a sp | 0.9% | — |
| CVE-2020-1579 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a special | 0.9% | — |
| CVE-2020-1550 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows CDP User Components improperly handle memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted app | 0.9% | — |
| CVE-2020-1266 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, | 0.9% | — |
| CVE-2020-1262 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1264, | 0.9% | — |
| CVE-2020-1247 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1251, CVE-2020-1253, | 0.9% | — |
| CVE-2026-50324 | MED 5.9 | microsoft windows_10_1607 Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | 0.9% | — |
| CVE-2024-43470 | HIGH 7.3 | microsoft azure_network_watcher_agent Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | 0.9% | — |