56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-0295 | MED 5.5 | microsoft windows_10 Microsoft Windows 10 1607 and 1703, and Windows Server 2016 allow an authenticated attacker to modify the C:\Users\DEFAULT folder structure, aka "Windows Default Folder Tampering Vulnerability". | 1.2% | — |
| CVE-2023-36722 | MED 4.4 | microsoft windows_10_1507 Active Directory Domain Services Information Disclosure Vulnerability | 1.2% | — |
| CVE-2020-16982 | MED 6.1 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1.2% | — |
| CVE-2023-32038 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2025-21342 | HIGH 8.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2020-0904 | MED 6.5 | microsoft windows_10 <p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.</p> <p>To exploit the vulnerability, an attacker who already has a privileged accoun | 1.2% | — |
| CVE-2020-0886 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.</p> <p>To exploit the vulnerability, an attacker wo | 1.2% | — |
| CVE-2025-29804 | HIGH 7.3 | microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | 1.2% | — |
| CVE-2024-49050 | HIGH 8.8 | microsoft python Visual Studio Code Python Extension Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2024-21326 | CRIT 9.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2020-17135 | MED 6.4 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 1.2% | — |
| CVE-2019-1391 | MED 5.5 | microsoft windows_10 A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2018-12207. | 1.2% | — |
| CVE-2024-26196 | MED 4.3 | microsoft edge Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability | 1.2% | — |
| CVE-2022-37962 | HIGH 7.8 | microsoft 365_apps Microsoft PowerPoint Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2026-50328 | HIGH 7.5 | microsoft windows_10_1607 Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network. | 1.2% | — |
| CVE-2023-24900 | MED 5.9 | microsoft windows_10_1507 Windows NTLM Security Support Provider Information Disclosure Vulnerability | 1.2% | — |
| CVE-2020-0634 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'. | 1.2% | — |
| CVE-2024-21399 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2022-30148 | MED 5.5 | microsoft windows_10 Windows Desired State Configuration (DSC) Information Disclosure Vulnerability | 1.2% | — |
| CVE-2022-29114 | MED 5.5 | microsoft windows_10 Windows Print Spooler Information Disclosure Vulnerability | 1.2% | — |
| CVE-2024-43487 | MED 6.5 | microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2023-36804 | HIGH 7.8 | microsoft windows_10_1507 Windows GDI Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2021-1648 | HIGH 7.8 | microsoft windows_10 Microsoft splwow64 Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2020-1455 | MED 5.3 | microsoft sql_server_management_studio A denial of service vulnerability exists when Microsoft SQL Server Management Studio (SSMS) improperly handles files. An attacker could exploit the vulnerability to trigger a denial of service. To exploit the vulnerability, an attacker would first require exec | 1.2% | — |
| CVE-2010-0485 | HIGH 7.8 | microsoft windows_2000 The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 "do not properly validate all callback parameters when creating a new windo | 1.2% | — |