56.784 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-29992 | MED 5.5 | microsoft azure_identity_library_for_.net Azure Identity Library for .NET Information Disclosure Vulnerability | 0.7% | — |
| CVE-2022-33675 | HIGH 7.8 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-26864 | HIGH 8.4 | microsoft windows_10 Windows Virtual Registry Provider Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-16989 | MED 5.4 | microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-1002 | HIGH 7.1 | microsoft forefront_endpoint_protection_2010 An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vu | 0.7% | — |
| CVE-2021-26413 | MED 6.2 | microsoft windows_10 Windows Installer Spoofing Vulnerability | 0.7% | — |
| CVE-2026-54120 | CRIT 9.9 | microsoft surface_management_services Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-54906 | HIGH 7.8 | microsoft 365_apps Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2024-38079 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-38070 | HIGH 7.8 | microsoft windows_10_1507 Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2022-23551 | MED 5.3 | microsoft azure_ad_pod_identity aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI component in AAD Pod Identity intercepts and validates token requests based on regex. In this case, a token request | 0.7% | — |
| CVE-2020-0785 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2026-62792 | HIGH 8.1 | microsoft windows_10_1607 Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-62825 | CRIT 10.0 | microsoft azure_key_vault Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-58275 | CRIT 10.0 | microsoft azure_dns Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2025-49746 | CRIT 9.9 | microsoft azure_machine_learning Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2025-25001 | MED 4.3 | microsoft edge Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2024-38223 | MED 6.8 | microsoft windows_10_1507 Windows Initial Machine Configuration Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-35625 | MED 4.7 | microsoft azure_machine_learning_software_development_kit Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability | 0.7% | — |
| CVE-2022-22031 | HIGH 7.8 | microsoft windows_10 Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-1437 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Network Location Awareness Service handles objects in memory, aka 'Windows Network Location Awareness Service Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2020-1428 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1373, CVE-2020 | 0.7% | — |
| CVE-2020-1399 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1249, CVE-2020-1353, CVE-2020-1370, CVE-2020-1404, CVE | 0.7% | — |
| CVE-2020-1395 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Speech Brokered API handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1388, CVE-2020-1392, CVE-2020-1394. | 0.7% | — |
| CVE-2020-1385 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Credential Picker handles objects in memory, aka 'Windows Credential Picker Elevation of Privilege Vulnerability'. | 0.7% | — |