56.747 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-41165 | HIGH 7.1 | microsoft word A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this | 0.7% | — |
| CVE-2020-1371 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Event Logging Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Event Logging Service Elevation of | 0.7% | — |
| CVE-2020-1363 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Picker Platform Elevation of Privilege Vu | 0.7% | — |
| CVE-2020-1352 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows USO Core Worker improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows USO Core Worker Elevation of Privilege Vu | 0.7% | — |
| CVE-2026-62835 | CRIT 9.3 | microsoft azure_portal Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2024-28921 | MED 6.7 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2025-24053 | HIGH 7.2 | microsoft dataverse Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-28903 | MED 6.7 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2026-47644 | MED 6.5 | microsoft copilot_chat Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2025-29820 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-21179 | MED 4.8 | microsoft windows_11_24h2 DHCP Client Service Denial of Service Vulnerability | 0.7% | — |
| CVE-2025-21257 | MED 5.5 | microsoft windows_10_1607 Windows WLAN AutoConfig Service Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-43626 | HIGH 7.8 | microsoft windows_10_1507 Windows Telephony Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-30041 | MED 5.4 | microsoft bing_search Microsoft Bing Search Spoofing Vulnerability | 0.7% | — |
| CVE-2021-41343 | MED 5.5 | microsoft windows_10 Windows Fast FAT File System Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-41336 | MED 5.5 | microsoft windows_11 Windows Kernel Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-40475 | MED 5.5 | microsoft windows_10 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-40472 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-40468 | MED 5.5 | microsoft windows_10 Windows Bind Filter Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-38663 | MED 5.5 | microsoft windows_10 Windows exFAT File System Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-29064 | MED 6.2 | microsoft windows_10_1507 Windows Hyper-V Denial of Service Vulnerability | 0.7% | — |
| CVE-2024-26241 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-22713 | MED 5.6 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0.7% | — |
| CVE-2022-21905 | MED 4.6 | microsoft windows_10 Windows Hyper-V Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2020-0822 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file operations, aka 'Windows Language Pack Installer Elevation of Privilege Vulnerability'. | 0.7% | — |