56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-0628 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- | 0.8% | — |
| CVE-2020-0627 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- | 0.8% | — |
| CVE-2020-0625 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- | 0.8% | — |
| CVE-2020-0623 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0625, CVE- | 0.8% | — |
| CVE-2020-0614 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0623, CVE-2020-0625, CVE- | 0.8% | — |
| CVE-2025-26637 | MED 6.8 | microsoft windows_10_1507 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0.8% | — |
| CVE-2024-43542 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43540 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43538 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43537 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2023-21749 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-41043 | LOW 3.3 | microsoft office Microsoft Office Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-33631 | HIGH 7.3 | microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2021-28309 | MED 5.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-27093 | MED 5.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-26417 | MED 5.5 | microsoft windows_10 Windows Overlay Filter Information Disclosure Vulnerability | 0.8% | — |
| CVE-2020-16922 | MED 5.3 | microsoft windows_10 <p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.</p> <p>In an attack scenario, an attacker could by | 0.8% | — |
| CVE-2025-29825 | MED 6.5 | microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.8% | — |
| CVE-2024-42004 | HIGH 7.1 | microsoft teams A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and | 0.8% | — |
| CVE-2023-35373 | MED 5.3 | microsoft mono Mono Authenticode Validation Spoofing Vulnerability | 0.8% | — |
| CVE-2022-29127 | MED 4.2 | microsoft windows_10 BitLocker Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2026-21226 | HIGH 7.5 | microsoft azure_core_shared_client_library Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-47161 | HIGH 7.8 | microsoft defender_for_endpoint Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | 0.8% | — |
| CVE-2022-29120 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-29102 | MED 5.5 | microsoft windows_server Windows Failover Cluster Information Disclosure Vulnerability | 0.8% | — |