56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-20828 | MED 4.6 | microsoft windows_10_1607 Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack. | 0.6% | — |
| CVE-2025-50169 | HIGH 7.5 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2025-47995 | MED 6.5 | microsoft azure_machine_learning Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2023-32041 | MED 5.5 | microsoft windows_10_1607 Windows Update Orchestrator Service Information Disclosure Vulnerability | 0.6% | — |
| CVE-2021-34493 | MED 6.7 | microsoft windows_10 Windows Partition Management Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-60727 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-54911 | HIGH 7.3 | microsoft windows_10_1507 Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2024-49074 | HIGH 7.8 | microsoft windows_10_1809 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-21802 | HIGH 7.8 | microsoft windows_10 Windows Media Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2022-23291 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-22001 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-21315 | HIGH 7.8 | microsoft windows_11_24h2 Microsoft Brokering File System Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-35797 | MED 6.1 | microsoft windows_10 Windows Hello Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2022-24459 | HIGH 7.8 | microsoft windows_10 Windows Fax and Scan Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2019-1454 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'. | 0.6% | — |
| CVE-2026-42981 | HIGH 8.1 | microsoft windows_11_23h2 Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-42974 | HIGH 8.1 | microsoft windows_11_23h2 Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2023-38173 | MED 4.3 | microsoft edge_chromium Microsoft Edge for Android Spoofing Vulnerability | 0.6% | — |
| CVE-2021-41372 | HIGH 7.6 | microsoft power_bi_report_server A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulne | 0.6% | — |
| CVE-2025-29837 | MED 5.5 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2024-21315 | HIGH 7.8 | microsoft defender_for_endpoint Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-34327 | HIGH 8.2 | microsoft partner_center Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-20862 | MED 5.5 | microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2024-26175 | HIGH 7.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2022-21834 | HIGH 7.0 | microsoft windows_10 Windows User-mode Driver Framework Reflector Driver Elevation of Privilege Vulnerability | 0.6% | — |