56.727 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.472 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-42826 | CRIT 10.0 | microsoft azure_devops Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-33819 | CRIT 10.0 | microsoft bing Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2022-38012 | HIGH 7.7 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2020-16993 | MED 5.4 | microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-38186 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-41031 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2021-42277 | MED 5.5 | microsoft visual_studio Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-26874 | HIGH 7.8 | microsoft windows_10 Windows Overlay Filter Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2026-50516 | CRIT 9.4 | microsoft azure_kubernetes_service Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2021-40489 | HIGH 7.8 | microsoft windows_10 Storage Spaces Controller Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-40478 | HIGH 7.8 | microsoft windows_10 Storage Spaces Controller Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-1077 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerabilit | 0.8% | — |
| CVE-2020-0763 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Defender Security Center handles certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Defender Security Center Elevation of Privil | 0.8% | — |
| CVE-2020-0762 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Defender Security Center handles certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Defender Security Center Elevation of Privil | 0.8% | — |
| CVE-2026-62785 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-33827 | HIGH 8.1 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2023-37143 | MED 5.5 | microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function BackwardPass::IsEmptyLoopAfterMemOp(). | 0.8% | — |
| CVE-2020-1590 | MED 6.6 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system.</p> < | 0.8% | — |
| CVE-2020-1465 | HIGH 7.8 | microsoft onedrive An elevation of privilege vulnerability exists in Microsoft OneDrive that allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft OneDrive Elevation of Privilege Vulnerabili | 0.8% | — |
| CVE-2026-26111 | HIGH 8.0 | microsoft windows_server_2012 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2023-36704 | HIGH 7.8 | microsoft windows_10_1809 Windows Setup Files Cleanup Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2023-28256 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2023-28255 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-35776 | MED 6.2 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Denial of Service Vulnerability | 0.8% | — |
| CVE-2022-21998 | MED 5.5 | microsoft windows_10 Windows Common Log File System Driver Information Disclosure Vulnerability | 0.8% | — |