56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-28898 | MED 6.3 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2022-33648 | HIGH 7.8 | microsoft office_online_server Microsoft Excel Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2020-17100 | MED 5.5 | microsoft visual_studio_2017 Visual Studio Tampering Vulnerability | 0.8% | — |
| CVE-2024-49094 | MED 6.6 | microsoft windows_10_1809 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-49081 | MED 6.6 | microsoft windows_10_1809 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-36422 | HIGH 7.8 | microsoft windows_defender Microsoft Windows Defender Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-33751 | HIGH 7.0 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-31952 | HIGH 7.8 | microsoft windows_10 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-0900 | MED 5.5 | microsoft visual_studio_2015 An elevation of privilege vulnerability exists when the Visual Studio Extension Installer Service improperly handles file operations, aka 'Visual Studio Extension Installer Service Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2020-0899 | MED 5.5 | microsoft visual_studio_2017 An elevation of privilege vulnerability exists when Microsoft Visual Studio updater service improperly handles file permissions, aka 'Microsoft Visual Studio Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2026-21516 | HIGH 8.8 | microsoft github_copilot Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2023-36416 | MED 6.1 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.8% | — |
| CVE-2021-1697 | HIGH 7.8 | microsoft windows_10 Windows InstallService Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1651 | HIGH 7.8 | microsoft visual_studio Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2019-1287 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Network Connectivity Assistant handles objects in memory, aka 'Windows Network Connectivity Assistant Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2019-1277 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Audio Service when a malformed parameter is processed, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2022-35771 | HIGH 7.8 | microsoft windows_10 Windows Defender Credential Guard Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2026-58612 | HIGH 7.4 | microsoft powershell Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-57104 | HIGH 8.8 | microsoft azure_storage_explorer Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-64667 | MED 5.3 | microsoft exchange_server User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 0.8% | — |
| CVE-2022-21903 | HIGH 7.0 | microsoft windows_10 Windows GDI Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2026-65660 | HIGH 8.8 | microsoft sharepoint_server Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2023-36732 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-26805 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2021-34466 | MED 5.7 | microsoft windows_10 Windows Hello Security Feature Bypass Vulnerability | 0.8% | — |