56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-43489 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2023-36404 | MED 5.5 | microsoft windows_10_1607 Windows Kernel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-27086 | HIGH 7.8 | microsoft windows_10 Windows Services and Controller App Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2025-62199 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.8% | — |
| CVE-2025-48802 | MED 6.5 | microsoft windows_11_22h2 Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network. | 0.8% | — |
| CVE-2021-31972 | MED 5.5 | microsoft windows_10 Event Tracing for Windows Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-31960 | MED 5.5 | microsoft windows_10 Windows Bind Filter Driver Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-31191 | MED 5.5 | microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28479 | MED 5.5 | microsoft windows_10 Windows CSC Service Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28446 | HIGH 7.1 | microsoft windows_10 Windows Portmapping Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28441 | MED 6.5 | microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28437 | MED 5.5 | microsoft windows_10 Windows Installer Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28435 | MED 5.5 | microsoft windows_10 Windows Event Tracing Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28318 | MED 5.5 | microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-21140 | MED 6.8 | google chrome Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a USB device. | 0.8% | — |
| CVE-2020-1405 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-13 | 0.8% | — |
| CVE-2020-1272 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system p | 0.8% | — |
| CVE-2020-1204 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2026-57988 | HIGH 7.1 | microsoft edge_chromium Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-47281 | CRIT 9.6 | microsoft visual_studio_code Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-20934 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-20848 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-21327 | MED 6.6 | microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2025-21265 | MED 6.6 | microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2025-21263 | MED 6.6 | microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability | 0.8% | — |