56.775 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-43877 | HIGH 8.8 | microsoft asp.net_core ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-47604 | HIGH 8.2 | microsoft nugetgallery NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code in a victim's browser. | 0.7% | — |
| CVE-2024-28920 | HIGH 7.8 | microsoft windows_10_1809 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2023-36898 | HIGH 7.8 | microsoft windows_11_21h2 Tablet Windows User Interface Application Core Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-43460 | HIGH 8.1 | microsoft dynamics_365_business_central Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2022-22717 | HIGH 7.0 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-41374 | MED 6.7 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-1680 | HIGH 7.8 | microsoft visual_studio Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-21214 | MED 4.2 | microsoft windows_10_1507 Windows BitLocker Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-38050 | HIGH 7.8 | microsoft windows_10_1507 Windows Workstation Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-30049 | HIGH 7.8 | microsoft windows_10_1507 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2019-1417 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1379, CVE-2019-1383. | 0.7% | — |
| CVE-2019-1383 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1379, CVE-2019-1417. | 0.7% | — |
| CVE-2019-1379 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1383, CVE-2019-1417. | 0.7% | — |
| CVE-2024-35261 | HIGH 7.8 | microsoft azure_network_watcher_agent Azure Network Watcher VM Extension Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-21750 | HIGH 7.1 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-16900 | HIGH 7.0 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Event System improperly handles objects in memory.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specia | 0.7% | — |
| CVE-2019-1177 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated | 0.7% | — |
| CVE-2019-1175 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticate | 0.7% | — |
| CVE-2019-1174 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally a | 0.7% | — |
| CVE-2026-32175 | MED 4.3 | microsoft .net A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker | 0.7% | — |
| CVE-2026-33109 | CRIT 9.9 | microsoft azure_managed_instance_for_apache_cassandra Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-62207 | HIGH 8.6 | microsoft azure_monitor Azure Monitor Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-30030 | HIGH 7.8 | microsoft windows_server_2008 Win32k Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-30028 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 0.7% | — |