56.743 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-0631 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- | 0.8% | — |
| CVE-2025-21363 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-40732 | MED 5.0 | microsoft windows_11_21h2 An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafte | 0.8% | — |
| CVE-2024-28902 | MED 5.5 | microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.8% | — |
| CVE-2024-26255 | MED 5.5 | microsoft windows_10_1809 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.8% | — |
| CVE-2024-26207 | MED 5.5 | microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.8% | — |
| CVE-2023-36398 | MED 6.5 | microsoft windows_10_1507 Windows NTFS Information Disclosure Vulnerability | 0.8% | — |
| CVE-2023-36428 | MED 5.5 | microsoft windows_10_1507 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | 0.8% | — |
| CVE-2023-36406 | MED 5.5 | microsoft windows_11_21h2 Windows Hyper-V Information Disclosure Vulnerability | 0.8% | — |
| CVE-2023-28240 | HIGH 8.8 | microsoft windows_server_2008 Windows Network Load Balancing Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2021-42303 | MED 6.6 | microsoft azure_real_time_operating_system Azure RTOS Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-0854 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2019-1380 | HIGH 7.8 | microsoft windows_10 A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2026-49169 | HIGH 8.0 | microsoft windows_server_2025 Use after free in DNS Server allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-47643 | CRIT 9.8 | microsoft azure_stack_edge External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2023-35389 | MED 6.5 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-24513 | HIGH 7.8 | microsoft visual_studio_2019 Visual Studio Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-38139 | HIGH 8.7 | microsoft dataverse Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2024-21340 | MED 4.6 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2026-49163 | HIGH 8.8 | microsoft application_insights_profiler Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-21264 | HIGH 7.1 | microsoft visual_studio_code Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0.8% | — |
| CVE-2025-21358 | HIGH 7.8 | microsoft windows_10_1507 Windows Core Messaging Elevation of Privileges Vulnerability | 0.8% | — |
| CVE-2025-21193 | MED 6.5 | microsoft windows_server_2016 Active Directory Federation Server Spoofing Vulnerability | 0.8% | — |
| CVE-2019-1447 | MED 5.4 | microsoft office_online_server A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1445. | 0.8% | — |
| CVE-2019-1445 | MED 5.4 | microsoft office_online_server A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'Microsoft Office Online Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1447. | 0.8% | — |