56.784 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1372 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles objects in memory, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE | 0.7% | — |
| CVE-2020-1368 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Credential Enrollment Manager service handles objects in memory, aka 'Windows Credential Enrollment Manager Service Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2020-1366 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Print Workflow Service improperly handles objects in memory, aka 'Windows Print Workflow Service Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2020-1360 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Profile Service improperly handles file operations, aka 'Windows Profile Service Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2020-1356 | HIGH 7.8 | microsoft windows_server_2012 An elevation of privilege vulnerability exists when the Windows iSCSI Target Service improperly handles file operations, aka 'Windows iSCSI Target Service Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2020-1353 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1249, CVE-2020-1370, CVE-2020-1399, CVE-2020-1404, CVE | 0.7% | — |
| CVE-2020-1085 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in memory, aka 'Windows Function Discovery Service Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2020-1279 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly load spotlight images from a secure location, aka 'Windows Lockscreen Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2020-1196 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the printconfig.dll handles objects in memory, aka 'Windows Print Configuration Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2026-50686 | HIGH 8.1 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-42895 | MED 6.5 | microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | 0.7% | — |
| CVE-2026-62899 | MED 5.9 | microsoft .net Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. | 0.7% | — |
| CVE-2026-33120 | HIGH 8.8 | microsoft sql_server_2016 Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-21288 | MED 6.5 | microsoft windows_10_1507 Windows COM Server Information Disclosure Vulnerability | 0.7% | — |
| CVE-2025-21272 | MED 6.5 | microsoft windows_10_1507 Windows COM Server Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-49052 | HIGH 8.2 | microsoft azure_functions Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-20658 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-41347 | HIGH 7.8 | microsoft windows_10 Windows AppX Deployment Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-28349 | HIGH 7.8 | microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2021-28348 | HIGH 7.8 | microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2020-1364 | HIGH 7.1 | microsoft windows_10 A denial of service vulnerability exists in the way that the WalletService handles files, aka 'Windows WalletService Denial of Service Vulnerability'. | 0.7% | — |
| CVE-2026-32186 | CRIT 10.0 | microsoft bing Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-33107 | CRIT 10.0 | microsoft azure_databricks Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-21430 | MED 5.7 | microsoft windows_10_1507 Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-36011 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 0.7% | — |