56.761 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-62827 | HIGH 8.8 | microsoft sharepoint_server Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-38133 | HIGH 7.8 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-26253 | MED 6.8 | microsoft windows_10_1507 Windows rndismp6.sys Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-26252 | MED 6.8 | microsoft windows_10_1507 Windows rndismp6.sys Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-28248 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-30213 | MED 5.5 | microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability | 0.7% | — |
| CVE-2026-21228 | HIGH 8.1 | microsoft azure_local Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2023-24882 | MED 5.5 | microsoft onedrive Microsoft OneDrive for Android Information Disclosure Vulnerability | 0.7% | — |
| CVE-2023-21794 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.7% | — |
| CVE-2020-17075 | HIGH 7.8 | microsoft windows_10 Windows USO Core Worker Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-1423 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Subsystem for Linux handles files, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2022-30222 | HIGH 8.4 | microsoft windows_10 Windows Shell Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2019-1289 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions, aka 'Windows Update Delivery Optimization Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2025-59285 | HIGH 7.0 | microsoft azure_monitor_agent Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2025-47162 | HIGH 8.4 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2024-20665 | MED 6.1 | microsoft windows_10_1507 BitLocker Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2020-0896 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Windows Hard Link Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0840, CVE-2020-0841, CVE-2020-0849. | 0.7% | — |
| CVE-2025-62550 | HIGH 8.8 | microsoft azure_monitor_agent Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-27737 | HIGH 8.6 | microsoft windows_10_1507 Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally. | 0.7% | — |
| CVE-2022-44694 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2021-26430 | MED 6.0 | microsoft azure_sphere Azure Sphere Denial of Service Vulnerability | 0.7% | — |
| CVE-2025-27483 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2020-16988 | MED 6.9 | microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2026-23662 | HIGH 7.5 | microsoft azure_iot_explorer Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2024-38254 | MED 5.5 | microsoft windows_10_1507 Windows Authentication Information Disclosure Vulnerability | 0.7% | — |