56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-24307 | CRIT 9.3 | microsoft 365_copilot Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2022-26803 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-26798 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2025-60722 | MED 6.5 | microsoft onedrive Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2022-44696 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-44695 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2021-38632 | MED 5.7 | microsoft windows_10 Windows BitLocker Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2025-47955 | HIGH 7.8 | microsoft windows_10_1507 Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 0.8% | — |
| CVE-2020-1254 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Modules Installer Service improperly handles class object members.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Modules Installer Service Elev | 0.8% | — |
| CVE-2020-1201 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way the Windows Now Playing Session Manager handles objects in memory, aka 'Windows Now Playing Session Manager Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2020-1199 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Feedback Hub improperly handles objects in memory, aka 'Windows Feedback Hub Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2020-1197 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2020-0916 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, aka 'Windows GDI Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0915. | 0.8% | — |
| CVE-2020-0915 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, aka 'Windows GDI Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0916. | 0.8% | — |
| CVE-2025-47997 | MED 6.5 | microsoft sql_server_2016 Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2024-35260 | HIGH 8.0 | microsoft power_platform An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network. | 0.8% | — |
| CVE-2021-1731 | MED 5.5 | microsoft windows_10 PFX Encryption Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2021-1661 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-0733 | HIGH 7.8 | microsoft windows_malicious_software_removal_tool An elevation of privilege vulnerability exists when the Windows Malicious Software Removal Tool (MSRT) improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Malicious Softw | 0.8% | — |
| CVE-2026-58594 | HIGH 8.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-57102 | HIGH 8.8 | microsoft visual_studio_code Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0.8% | — |
| CVE-2026-57094 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-57090 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-50474 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-50380 | CRIT 9.6 | microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | 0.8% | — |