56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-26796 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-26792 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-26787 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-43243 | MED 5.5 | microsoft vp9_video_extensions VP9 Video Extensions Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-43235 | MED 5.5 | microsoft windows_10 Storage Spaces Controller Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-43227 | MED 5.5 | microsoft windows_10 Storage Spaces Controller Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28317 | MED 5.5 | microsoft windows_10 Microsoft Windows Codecs Library Information Disclosure Vulnerability | 0.8% | — |
| CVE-2023-36739 | HIGH 7.8 | microsoft 3d_viewer 3D Viewer Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-41064 | MED 5.8 | microsoft .net_framework .NET Framework Information Disclosure Vulnerability | 0.8% | — |
| CVE-2020-0935 | MED 5.5 | microsoft onedrive An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneDrive for Windows Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2026-59115 | CRIT 9.9 | microsoft entra_provisioning_service '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-32174 | HIGH 7.7 | microsoft azure_ai_bot_service Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-21253 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally. | 0.8% | — |
| CVE-2025-21397 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-43603 | MED 5.5 | microsoft visual_studio Visual Studio Collector Service Denial of Service Vulnerability | 0.8% | — |
| CVE-2022-22022 | HIGH 7.1 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2025-27741 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | 0.8% | — |
| CVE-2022-41105 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-41104 | MED 5.5 | microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2022-41060 | MED 5.5 | microsoft 365_apps Microsoft Word Information Disclosure Vulnerability | 0.8% | — |
| CVE-2024-38161 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2025-59244 | MED 6.5 | microsoft windows_10_1507 External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network. | 0.8% | — |
| CVE-2025-58739 | MED 6.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. | 0.8% | — |
| CVE-2025-27484 | HIGH 7.5 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2023-21822 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 0.8% | — |