56.807 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-38252 | HIGH 7.8 | microsoft windows_10_1607 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-70340 | HIGH 8.1 | microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-26123 | MED 5.5 | microsoft authenticator Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-47169 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2023-32027 | HIGH 7.8 | microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-32025 | HIGH 7.8 | microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-29356 | HIGH 7.8 | microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-29349 | HIGH 7.8 | microsoft odbc_driver_for_sql_server Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2021-42300 | MED 6.0 | microsoft azure_sphere Azure Sphere Tampering Vulnerability | 0.6% | — |
| CVE-2020-1152 | MED 5.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system.</p> <p>To exploit the vulnerability, an attacke | 0.6% | — |
| CVE-2026-47653 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2025-29834 | HIGH 7.5 | microsoft edge_chromium Out-of-bounds read in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2022-22023 | MED 6.6 | microsoft windows_10 Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2026-42823 | CRIT 9.9 | microsoft azure_logic_apps Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2025-27739 | HIGH 7.8 | microsoft windows_10_1809 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-27731 | HIGH 7.8 | microsoft windows_10_1809 Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-27730 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-27476 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-27467 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-26674 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-26666 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-21337 | LOW 3.3 | microsoft windows_10_1507 Windows NTFS Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-37979 | HIGH 7.8 | microsoft windows_10 Windows Hyper-V Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-33761 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-65791 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | 0.6% | — |