IT
56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.477 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-38055 MED 5.5 microsoft windows_10_1507 Microsoft Windows Codecs Library Information Disclosure Vulnerability 0.8%
CVE-2022-23263 HIGH 7.7 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 0.8%
CVE-2021-26442 HIGH 7.0 microsoft windows_10 Windows HTTP.sys Elevation of Privilege Vulnerability 0.8%
CVE-2021-26890 HIGH 7.8 microsoft windows_10 Application Virtualization Remote Code Execution Vulnerability 0.8%
CVE-2026-40415 HIGH 8.1 microsoft windows_10_1809 Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-55326 HIGH 7.5 microsoft windows_10_1809 Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2024-38183 CRIT 9.8 microsoft groupme An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network. 0.8%
CVE-2022-23297 MED 5.5 microsoft windows_10 Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability 0.8%
CVE-2022-23252 MED 5.5 microsoft 365_apps Microsoft Office Information Disclosure Vulnerability 0.8%
CVE-2022-21985 MED 5.5 microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability 0.8%
CVE-2021-41373 MED 5.5 microsoft fslogix FSLogix Information Disclosure Vulnerability 0.8%
CVE-2020-0944 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE 0.8%
CVE-2020-0919 HIGH 7.8 microsoft windows_app An elevation of privilege vulnerability exists in Remote Desktop App for Mac in the way it allows an attacker to load unsigned binaries, aka 'Microsoft Remote Desktop App for Mac Elevation of Privilege Vulnerability'. 0.8%
CVE-2020-0793 HIGH 7.8 microsoft visual_studio_2015 An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. 0.8%
CVE-2020-0752 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0666, CVE-2020-0667, CVE-2020-0735. 0.8%
CVE-2020-0747 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0659. 0.8%
CVE-2020-0739 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the dssvc.dll handles file creation allowing for a file overwrite or creation in a secured location, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0737. 0.8%
CVE-2020-0737 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the tapisrv.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0739. 0.8%
CVE-2020-0735 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0666, CVE-2020-0667, CVE-2020-0752. 0.8%
CVE-2020-0701 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Client License Service (ClipSVC) handles objects in memory, aka 'Windows Client License Service Elevation of Privilege Vulnerability'. 0.8%
CVE-2020-0667 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0666, CVE-2020-0735, CVE-2020-0752. 0.8%
CVE-2026-58617 HIGH 8.1 microsoft 365_copilot Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. 0.8%
CVE-2026-47287 MED 6.5 microsoft visual_studio_code Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. 0.8%
CVE-2025-53792 CRIT 9.1 microsoft azure_portal Azure Portal Elevation of Privilege Vulnerability 0.8%
CVE-2024-38175 CRIT 9.6 microsoft azure_managed_instance_for_apache_cassandra An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network. 0.8%