IT
56.721 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.472 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-31937 HIGH 8.2 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 0.9%
CVE-2022-24527 HIGH 7.8 microsoft endpoint_configuration_manager Microsoft Endpoint Configuration Manager Elevation of Privilege Vulnerability 0.9%
CVE-2020-1088 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfully exploited the vul 0.9%
CVE-2025-27736 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally. 0.8%
CVE-2024-38105 MED 6.5 microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability 0.8%
CVE-2024-38102 MED 6.5 microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability 0.8%
CVE-2024-38101 MED 6.5 microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability 0.8%
CVE-2024-21384 HIGH 7.8 microsoft 365_apps Microsoft Office OneNote Remote Code Execution Vulnerability 0.8%
CVE-2020-0750 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0740, CVE-2020-0 0.8%
CVE-2020-0749 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0740, CVE-2020-0 0.8%
CVE-2020-0743 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0740, CVE-2020-0 0.8%
CVE-2020-0742 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0740, CVE-2020-0 0.8%
CVE-2020-0741 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0740, CVE-2020-0 0.8%
CVE-2020-0740 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0741, CVE-2020-0 0.8%
CVE-2020-0727 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'. 0.8%
CVE-2020-0680 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in memory, aka 'Windows Function Discovery Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0679, CVE-2020-0 0.8%
CVE-2020-0679 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in memory, aka 'Windows Function Discovery Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0680, CVE-2020-0 0.8%
CVE-2020-0666 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0667, CVE-2020-0735, CVE-2020-0752. 0.8%
CVE-2020-0659 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0747. 0.8%
CVE-2020-0657 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'. 0.8%
CVE-2020-0613 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE- 0.8%
CVE-2023-24923 MED 5.5 microsoft onedrive Microsoft OneDrive for Android Information Disclosure Vulnerability 0.8%
CVE-2022-24550 HIGH 7.8 microsoft windows_10 Windows Telephony Server Elevation of Privilege Vulnerability 0.8%
CVE-2020-1163 HIGH 7.8 microsoft forefront_endpoint_protection_2010 An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulne 0.8%
CVE-2025-50164 HIGH 8.0 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0.8%