56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-21261 | MED 6.6 | microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-38238 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming Service Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-36726 | HIGH 7.8 | microsoft windows_10_1507 Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-36866 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2023-36865 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-22048 | MED 6.1 | microsoft windows_10 BitLocker Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2022-26786 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2026-47645 | HIGH 8.8 | microsoft 365_copilot Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-47160 | MED 5.4 | microsoft windows_10_1507 Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | 0.8% | — |
| CVE-2023-36418 | HIGH 7.8 | microsoft azure_rtos_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-21309 | HIGH 7.8 | microsoft windows_11_21h2 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-20682 | HIGH 7.8 | microsoft windows_10_1507 Windows Cryptographic Services Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2026-56191 | CRIT 10.0 | microsoft exchange_online Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. | 0.8% | — |
| CVE-2026-47655 | MED 6.5 | microsoft graph Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2024-38119 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-38057 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-38034 | HIGH 7.8 | microsoft windows_10_1507 Windows Filtering Platform Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-33162 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-1727 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-1306 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE | 0.8% | — |
| CVE-2020-0868 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka 'Windows Update Orchestrator Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0867. | 0.8% | — |
| CVE-2020-0867 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka 'Windows Update Orchestrator Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0868. | 0.8% | — |
| CVE-2020-0857 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2020-0844 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2020-0808 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way the Provisioning Runtime validates certain file operations, aka 'Provisioning Runtime Elevation of Privilege Vulnerability'. | 0.8% | — |