IT
56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.477 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-24307 CRIT 9.3 microsoft 365_copilot Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. 0.8%
CVE-2022-26803 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.8%
CVE-2022-26798 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.8%
CVE-2025-60722 MED 6.5 microsoft onedrive Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2022-44696 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0.8%
CVE-2022-44695 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0.8%
CVE-2021-38632 MED 5.7 microsoft windows_10 Windows BitLocker Security Feature Bypass Vulnerability 0.8%
CVE-2025-47955 HIGH 7.8 microsoft windows_10_1507 Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. 0.8%
CVE-2020-1254 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows Modules Installer Service improperly handles class object members.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Modules Installer Service Elev 0.8%
CVE-2020-1201 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way the Windows Now Playing Session Manager handles objects in memory, aka 'Windows Now Playing Session Manager Elevation of Privilege Vulnerability'. 0.8%
CVE-2020-1199 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Feedback Hub improperly handles objects in memory, aka 'Windows Feedback Hub Elevation of Privilege Vulnerability'. 0.8%
CVE-2020-1197 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. 0.8%
CVE-2020-0916 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, aka 'Windows GDI Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0915. 0.8%
CVE-2020-0915 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, aka 'Windows GDI Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0916. 0.8%
CVE-2025-47997 MED 6.5 microsoft sql_server_2016 Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network. 0.8%
CVE-2024-35260 HIGH 8.0 microsoft power_platform An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network. 0.8%
CVE-2021-1731 MED 5.5 microsoft windows_10 PFX Encryption Security Feature Bypass Vulnerability 0.8%
CVE-2021-1661 HIGH 7.8 microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability 0.8%
CVE-2020-0733 HIGH 7.8 microsoft windows_malicious_software_removal_tool An elevation of privilege vulnerability exists when the Windows Malicious Software Removal Tool (MSRT) improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Malicious Softw 0.8%
CVE-2026-58594 HIGH 8.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-57102 HIGH 8.8 microsoft visual_studio_code Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. 0.8%
CVE-2026-57094 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-57090 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-50474 HIGH 8.8 microsoft windows_10_1607 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-50380 CRIT 9.6 microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. 0.8%