56.743 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-49044 | MED 6.7 | microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-38166 | HIGH 8.2 | microsoft dynamics_crm_service_portal_web_resource An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link. | 0.8% | — |
| CVE-2023-38161 | HIGH 7.8 | microsoft windows_10_1507 Windows GDI Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-32051 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2021-43246 | MED 5.6 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0.8% | — |
| CVE-2026-70306 | CRIT 9.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2025-62222 | HIGH 8.8 | microsoft github_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-21416 | HIGH 8.5 | microsoft azure_virtual_desktop Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2023-23420 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-34514 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-0632 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- | 0.7% | — |
| CVE-2020-0630 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- | 0.7% | — |
| CVE-2020-0629 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- | 0.7% | — |
| CVE-2020-0626 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- | 0.7% | — |
| CVE-2020-0620 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Microsoft Cryptographic Services improperly handles files, aka 'Microsoft Cryptographic Services Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2026-42833 | CRIT 9.1 | microsoft dynamics_365 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-49674 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2024-37984 | HIGH 8.4 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-29989 | HIGH 8.4 | microsoft azure_monitor_agent Azure Monitor Agent Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-28309 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.7% | — |
| CVE-2026-35423 | MED 5.4 | microsoft windows_10_1607 Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-32151 | MED 6.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2025-21361 | HIGH 7.8 | microsoft office Microsoft Outlook Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2025-21187 | HIGH 7.8 | microsoft power_automate_for_desktop Microsoft Power Automate Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-43505 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.7% | — |