IT
56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.477 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-0628 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- 0.8%
CVE-2020-0627 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- 0.8%
CVE-2020-0625 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- 0.8%
CVE-2020-0623 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0625, CVE- 0.8%
CVE-2020-0614 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0623, CVE-2020-0625, CVE- 0.8%
CVE-2025-26637 MED 6.8 microsoft windows_10_1507 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.8%
CVE-2024-43542 MED 6.5 microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability 0.8%
CVE-2024-43540 MED 6.5 microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability 0.8%
CVE-2024-43538 MED 6.5 microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability 0.8%
CVE-2024-43537 MED 6.5 microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability 0.8%
CVE-2023-21749 HIGH 7.8 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0.8%
CVE-2022-41043 LOW 3.3 microsoft office Microsoft Office Information Disclosure Vulnerability 0.8%
CVE-2022-33631 HIGH 7.3 microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability 0.8%
CVE-2021-28309 MED 5.5 microsoft windows_10 Windows Kernel Information Disclosure Vulnerability 0.8%
CVE-2021-27093 MED 5.5 microsoft windows_10 Windows Kernel Information Disclosure Vulnerability 0.8%
CVE-2021-26417 MED 5.5 microsoft windows_10 Windows Overlay Filter Information Disclosure Vulnerability 0.8%
CVE-2020-16922 MED 5.3 microsoft windows_10 <p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.</p> <p>In an attack scenario, an attacker could by 0.8%
CVE-2025-29825 MED 6.5 microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.8%
CVE-2024-42004 HIGH 7.1 microsoft teams A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and 0.8%
CVE-2023-35373 MED 5.3 microsoft mono Mono Authenticode Validation Spoofing Vulnerability 0.8%
CVE-2022-29127 MED 4.2 microsoft windows_10 BitLocker Security Feature Bypass Vulnerability 0.8%
CVE-2026-21226 HIGH 7.5 microsoft azure_core_shared_client_library Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network. 0.8%
CVE-2025-47161 HIGH 7.8 microsoft defender_for_endpoint Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. 0.8%
CVE-2022-29120 MED 6.5 microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability 0.8%
CVE-2022-29102 MED 5.5 microsoft windows_server Windows Failover Cluster Information Disclosure Vulnerability 0.8%