56.736 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.474 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1232 | HIGH 7.8 | microsoft visual_studio An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations, aka 'Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2025-25007 | MED 5.3 | microsoft exchange_server Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 0.8% | — |
| CVE-2023-21747 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-41107 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2020-1245 | HIGH 7.0 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install | 0.8% | — |
| CVE-2021-43211 | MED 5.5 | microsoft windows_10_update_assistant Windows 10 Update Assistant Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2026-49179 | HIGH 8.8 | microsoft windows_10_1607 Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-41098 | HIGH 8.4 | microsoft azure_stack_edge Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network. | 0.8% | — |
| CVE-2022-30223 | MED 5.7 | microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability | 0.8% | — |
| CVE-2026-26151 | HIGH 7.1 | microsoft windows_10_1607 Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network. | 0.8% | — |
| CVE-2025-21194 | HIGH 7.1 | microsoft surface_go_2_1901_firmware Microsoft Surface Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2024-43529 | HIGH 7.3 | microsoft windows_10_21h2 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-35255 | MED 5.5 | microsoft authentication_library Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-35773 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-34687 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2019-1176 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delet | 0.8% | — |
| CVE-2026-61924 | MED 6.5 | microsoft windows_10_1607 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-61921 | MED 6.5 | microsoft windows_10_1607 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2023-37142 | MED 5.5 | microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees(). | 0.8% | — |
| CVE-2023-37141 | MED 5.5 | microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers::ProfiledNewScArray(). | 0.8% | — |
| CVE-2023-37140 | MED 5.5 | microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::DiagScopeVariablesWalker::GetChildrenCount(). | 0.8% | — |
| CVE-2026-41105 | HIGH 8.1 | microsoft azure_monitor_action_group_notification_system Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-32211 | CRIT 9.1 | microsoft azure_web_apps Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2025-21394 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2025-21392 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 0.8% | — |