56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-20821 | MED 6.2 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally. | 0.7% | — |
| CVE-2025-27733 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2024-38078 | HIGH 7.5 | microsoft windows_11_21h2 Xbox Wireless Adapter Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-21738 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2026-59113 | HIGH 8.8 | microsoft visual_studio_code Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2024-38247 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-38046 | HIGH 7.8 | microsoft windows_10_1507 PowerShell Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-36868 | MED 6.5 | microsoft azure_service_fabric Azure Service Fabric on Windows Information Disclosure Vulnerability | 0.7% | — |
| CVE-2023-23375 | HIGH 7.8 | microsoft odbc Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2026-21235 | HIGH 7.3 | microsoft windows_10_1607 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2026-20946 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-48822 | HIGH 8.6 | microsoft windows_10_1607 Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2024-38117 | HIGH 7.8 | microsoft windows_10_1507 NTFS Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-36717 | MED 6.5 | microsoft windows_10_1507 Windows Virtual Trusted Platform Module Denial of Service Vulnerability | 0.7% | — |
| CVE-2023-38170 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-36869 | MED 6.3 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 0.7% | — |
| CVE-2022-29135 | HIGH 7.0 | microsoft windows_server Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-26880 | HIGH 7.8 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-26872 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-26870 | HIGH 7.8 | microsoft windows_10 Windows Projected File System Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-24042 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-26217 | MED 5.5 | microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.7% | — |
| CVE-2022-21858 | HIGH 7.8 | microsoft windows_10 Windows Bind Filter Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-21852 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2026-58595 | HIGH 8.1 | microsoft bing_search Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |