56.790 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-24953 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-47213 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-47212 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-44682 | MED 6.8 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0.7% | — |
| CVE-2022-38030 | MED 4.3 | microsoft windows_10 Windows USB Serial Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2026-58597 | MED 4.3 | microsoft edge_chromium Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2025-49713 | HIGH 8.8 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-32713 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2022-44704 | HIGH 7.8 | microsoft windows_sysmon Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-21836 | HIGH 7.8 | microsoft windows_10 Windows Certificate Spoofing Vulnerability | 0.7% | — |
| CVE-2026-23661 | HIGH 7.5 | microsoft azure_iot_explorer Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2025-53149 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2020-1312 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins | 0.7% | — |
| CVE-2020-1302 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins | 0.7% | — |
| CVE-2020-1277 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins | 0.7% | — |
| CVE-2023-21773 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-41092 | HIGH 7.8 | microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-1334 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE | 0.7% | — |
| CVE-2020-1265 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1282, CVE | 0.7% | — |
| CVE-2026-50369 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-21515 | CRIT 9.9 | microsoft azure_iot_central Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2021-43231 | HIGH 7.8 | microsoft windows_10 Windows NTFS Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-40441 | HIGH 7.8 | microsoft windows_7 Windows Media Center Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-26685 | MED 6.5 | microsoft defender_for_identity Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network. | 0.7% | — |
| CVE-2025-24082 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.7% | — |