56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36042 | MED 6.2 | microsoft visual_studio_2019 Visual Studio Denial of Service Vulnerability | 0.8% | — |
| CVE-2021-33744 | MED 5.3 | microsoft windows_10 Windows Secure Kernel Mode Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2020-0942 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE | 0.8% | — |
| CVE-2020-0936 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when a Windows scheduled task improperly handles file redirections, aka 'Windows Scheduled Task Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2026-32191 | CRIT 9.8 | microsoft bing_images Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-20931 | HIGH 8.0 | microsoft windows_10_1607 External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network. | 0.8% | — |
| CVE-2025-27747 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.8% | — |
| CVE-2022-29134 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-29123 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-29122 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-26930 | MED 5.5 | microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-22011 | MED 5.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 0.8% | — |
| CVE-2020-0772 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Error Reporting improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Error Reporting Elevation of Privilege Vulner | 0.8% | — |
| CVE-2019-1415 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins | 0.8% | — |
| CVE-2025-21274 | MED 5.5 | microsoft windows_10_1507 Windows Event Tracing Denial of Service Vulnerability | 0.8% | — |
| CVE-2020-17012 | HIGH 7.8 | microsoft windows_10 Windows Bind Filter Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-1347 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations, aka 'Windows Storage Services Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2020-1293 | HIGH 7.8 | microsoft visual_studio An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1257, CVE- | 0.8% | — |
| CVE-2020-1278 | HIGH 7.8 | microsoft visual_studio An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1257, CVE- | 0.8% | — |
| CVE-2020-1257 | HIGH 7.8 | microsoft visual_studio An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1278, CVE- | 0.8% | — |
| CVE-2002-0051 | HIGH 7.8 | microsoft windows_2000 Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access. | 0.8% | — |
| CVE-2025-53783 | HIGH 7.5 | microsoft dynamics_365_guides Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2023-38154 | HIGH 7.8 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-44692 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2025-55242 | MED 6.5 | microsoft xbox_gaming_services Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose information over a network. | 0.8% | — |