IT
56.784 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.477 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-1372 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles objects in memory, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE 0.7%
CVE-2020-1368 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Credential Enrollment Manager service handles objects in memory, aka 'Windows Credential Enrollment Manager Service Elevation of Privilege Vulnerability'. 0.7%
CVE-2020-1366 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Print Workflow Service improperly handles objects in memory, aka 'Windows Print Workflow Service Elevation of Privilege Vulnerability'. 0.7%
CVE-2020-1360 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Profile Service improperly handles file operations, aka 'Windows Profile Service Elevation of Privilege Vulnerability'. 0.7%
CVE-2020-1356 HIGH 7.8 microsoft windows_server_2012 An elevation of privilege vulnerability exists when the Windows iSCSI Target Service improperly handles file operations, aka 'Windows iSCSI Target Service Elevation of Privilege Vulnerability'. 0.7%
CVE-2020-1353 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1249, CVE-2020-1370, CVE-2020-1399, CVE-2020-1404, CVE 0.7%
CVE-2020-1085 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in memory, aka 'Windows Function Discovery Service Elevation of Privilege Vulnerability'. 0.7%
CVE-2020-1279 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly load spotlight images from a secure location, aka 'Windows Lockscreen Elevation of Privilege Vulnerability'. 0.7%
CVE-2020-1196 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the printconfig.dll handles objects in memory, aka 'Windows Print Configuration Elevation of Privilege Vulnerability'. 0.7%
CVE-2026-50686 HIGH 8.1 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2026-42895 MED 6.5 microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. 0.7%
CVE-2026-62899 MED 5.9 microsoft .net Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. 0.7%
CVE-2026-33120 HIGH 8.8 microsoft sql_server_2016 Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network. 0.7%
CVE-2025-21288 MED 6.5 microsoft windows_10_1507 Windows COM Server Information Disclosure Vulnerability 0.7%
CVE-2025-21272 MED 6.5 microsoft windows_10_1507 Windows COM Server Information Disclosure Vulnerability 0.7%
CVE-2024-49052 HIGH 8.2 microsoft azure_functions Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2024-20658 HIGH 7.8 microsoft windows_10_1507 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability 0.7%
CVE-2021-41347 HIGH 7.8 microsoft windows_10 Windows AppX Deployment Service Elevation of Privilege Vulnerability 0.7%
CVE-2021-28349 HIGH 7.8 microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability 0.7%
CVE-2021-28348 HIGH 7.8 microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability 0.7%
CVE-2020-1364 HIGH 7.1 microsoft windows_10 A denial of service vulnerability exists in the way that the WalletService handles files, aka 'Windows WalletService Denial of Service Vulnerability'. 0.7%
CVE-2026-32186 CRIT 10.0 microsoft bing Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2026-33107 CRIT 10.0 microsoft azure_databricks Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2024-21430 MED 5.7 microsoft windows_10_1507 Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability 0.7%
CVE-2023-36011 HIGH 7.8 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 0.7%