IT
56.784 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.477 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-29992 MED 5.5 microsoft azure_identity_library_for_.net Azure Identity Library for .NET Information Disclosure Vulnerability 0.7%
CVE-2022-33675 HIGH 7.8 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 0.7%
CVE-2021-26864 HIGH 8.4 microsoft windows_10 Windows Virtual Registry Provider Elevation of Privilege Vulnerability 0.7%
CVE-2020-16989 MED 5.4 microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability 0.7%
CVE-2020-1002 HIGH 7.1 microsoft forefront_endpoint_protection_2010 An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vu 0.7%
CVE-2021-26413 MED 6.2 microsoft windows_10 Windows Installer Spoofing Vulnerability 0.7%
CVE-2026-54120 CRIT 9.9 microsoft surface_management_services Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. 0.7%
CVE-2025-54906 HIGH 7.8 microsoft 365_apps Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally. 0.7%
CVE-2024-38079 HIGH 7.8 microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability 0.7%
CVE-2024-38070 HIGH 7.8 microsoft windows_10_1507 Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability 0.7%
CVE-2022-23551 MED 5.3 microsoft azure_ad_pod_identity aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI component in AAD Pod Identity intercepts and validates token requests based on regex. In this case, a token request 0.7%
CVE-2020-0785 HIGH 7.1 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'. 0.7%
CVE-2026-62792 HIGH 8.1 microsoft windows_10_1607 Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2026-62825 CRIT 10.0 microsoft azure_key_vault Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2026-58275 CRIT 10.0 microsoft azure_dns Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2025-49746 CRIT 9.9 microsoft azure_machine_learning Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2025-25001 MED 4.3 microsoft edge Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.7%
CVE-2024-38223 MED 6.8 microsoft windows_10_1507 Windows Initial Machine Configuration Elevation of Privilege Vulnerability 0.7%
CVE-2023-35625 MED 4.7 microsoft azure_machine_learning_software_development_kit Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability 0.7%
CVE-2022-22031 HIGH 7.8 microsoft windows_10 Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability 0.7%
CVE-2020-1437 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Network Location Awareness Service handles objects in memory, aka 'Windows Network Location Awareness Service Elevation of Privilege Vulnerability'. 0.7%
CVE-2020-1428 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1373, CVE-2020 0.7%
CVE-2020-1399 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1249, CVE-2020-1353, CVE-2020-1370, CVE-2020-1404, CVE 0.7%
CVE-2020-1395 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Speech Brokered API handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1388, CVE-2020-1392, CVE-2020-1394. 0.7%
CVE-2020-1385 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Credential Picker handles objects in memory, aka 'Windows Credential Picker Elevation of Privilege Vulnerability'. 0.7%