56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-26914 | HIGH 7.8 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-24546 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-1488 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. To exploit this vulnerability, an authenticated attacker would need to run a specially cra | 0.8% | — |
| CVE-2026-57087 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-50487 | HIGH 8.1 | microsoft windows_11_24h2 Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-50439 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-54995 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-50694 | HIGH 8.1 | microsoft windows_10_1607 Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-49164 | HIGH 8.1 | microsoft windows_10_1607 Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-21523 | HIGH 8.0 | microsoft visual_studio_code Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2024-30016 | MED 5.5 | microsoft windows_10_1507 Windows Cryptographic Services Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28350 | HIGH 7.8 | microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2020-1430 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows UPnP Device Host Elevation of Privilege | 0.8% | — |
| CVE-2020-1365 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Event Logging Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Event Logging Service Elevation of | 0.8% | — |
| CVE-2020-1354 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows UPnP Device Host Elevation of Privilege | 0.8% | — |
| CVE-2020-1271 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Service Elevation of Privi | 0.8% | — |
| CVE-2020-1222 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Microsoft Store Runtime Elevation of Privilege Vu | 0.8% | — |
| CVE-2025-62452 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-60715 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-21373 | HIGH 7.8 | microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-30064 | HIGH 8.8 | microsoft windows_server_2022 Windows Kernel Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-35309 | HIGH 7.5 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2023-33154 | HIGH 7.8 | microsoft windows_10_1507 Windows Partition Management Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-38198 | HIGH 7.5 | microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-38056 | MED 5.5 | microsoft windows_10_1507 Microsoft Windows Codecs Library Information Disclosure Vulnerability | 0.8% | — |