56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-33636 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2026-33096 | HIGH 7.5 | microsoft windows_11_23h2 Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2024-30045 | MED 6.3 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2005-2765 | LOW 2.1 | microsoft windows_2003_server The user interface in the Windows Firewall does not properly display certain malformed entries in the Windows Registry, which makes it easier for attackers with administrator privileges to hide activities if the administrator only uses the Windows Firewall int | 1.2% | — |
| CVE-2020-16961 | HIGH 7.8 | microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2020-16960 | HIGH 7.8 | microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2017-8576 | HIGH 7.0 | microsoft windows_10 The graphics component in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to run arbitrary code in kernel mode via a specially crafted application, aka "Microsoft Graphics Component Elevation of Privilege V | 1.2% | — |
| CVE-2022-22035 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2020-1116 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the use | 1.2% | — |
| CVE-2020-1072 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerabili | 1.2% | — |
| CVE-2022-34702 | HIGH 8.1 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2026-21248 | HIGH 7.3 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | 1.2% | — |
| CVE-2026-21244 | HIGH 7.3 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | 1.2% | — |
| CVE-2025-21173 | HIGH 7.3 | microsoft .net .NET Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2020-16897 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p | 1.2% | — |
| CVE-2022-34704 | MED 4.7 | microsoft windows_10 Windows Defender Credential Guard Information Disclosure Vulnerability | 1.2% | — |
| CVE-2018-0820 | HIGH 7.8 | microsoft windows_10 The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulne | 1.2% | — |
| CVE-2018-0742 | HIGH 7.8 | microsoft windows_10 The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulne | 1.2% | — |
| CVE-2024-28925 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2018-8117 | MED 6.8 | microsoft wireless_keyboard_850 A security feature bypass vulnerability exists in the Microsoft Wireless Keyboard 850 which could allow an attacker to reuse an AES encryption key to send keystrokes to other keyboard devices or to read keystrokes sent by other keyboards for the affected devic | 1.2% | — |
| CVE-2024-21448 | MED 5.0 | microsoft teams Microsoft Teams for Android Information Disclosure Vulnerability | 1.2% | — |
| CVE-2023-36009 | MED 5.5 | microsoft 365_apps Microsoft Word Information Disclosure Vulnerability | 1.2% | — |
| CVE-2023-32056 | HIGH 7.8 | microsoft windows_10_1809 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2021-26418 | MED 4.6 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1.2% | — |
| CVE-2024-49048 | HIGH 8.1 | microsoft torchgeo TorchGeo Remote Code Execution Vulnerability | 1.2% | — |