56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2011-1874 | HIGH 7.8 | microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain | 1.2% | — |
| CVE-2023-21539 | HIGH 7.5 | microsoft windows_10_20h2 Windows Authentication Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2024-28899 | HIGH 8.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2023-36037 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2019-1211 | HIGH 7.3 | microsoft visual_studio_2017 An elevation of privilege vulnerability exists in Git for Visual Studio when it improperly parses configuration files. An attacker who successfully exploited the vulnerability could execute code in the context of another local user. To exploit the vulnerabilit | 1.2% | — |
| CVE-2026-26105 | HIGH 8.1 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 1.2% | — |
| CVE-2024-38263 | HIGH 7.5 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2026-20929 | HIGH 7.5 | microsoft windows_10_1607 Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. | 1.2% | — |
| CVE-2025-26668 | HIGH 7.5 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1.2% | — |
| CVE-2020-1033 | MED 4.0 | microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>An authenticated | 1.2% | — |
| CVE-2017-8579 | HIGH 7.0 | microsoft windows_10 The DirectX component in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to run arbitrary code in kernel mode via a specially crafted application, aka "DirectX Elevation of Privilege Vulnerability." | 1.2% | — |
| CVE-2024-21396 | HIGH 7.6 | microsoft dynamics_365 Dynamics 365 Sales Spoofing Vulnerability | 1.2% | — |
| CVE-2024-21393 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 1.2% | — |
| CVE-2024-21389 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 1.2% | — |
| CVE-2021-26862 | HIGH 7.0 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2019-1088 | HIGH 7.8 | microsoft windows_10 An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1086, CVE-2019-1087. | 1.2% | — |
| CVE-2019-1087 | HIGH 7.8 | microsoft windows_10 An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1086, CVE-2019-1088. | 1.2% | — |
| CVE-2019-1086 | HIGH 7.8 | microsoft windows_10 An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1087, CVE-2019-1088. | 1.2% | — |
| CVE-2019-1085 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the wlansvc.dll handles objects in memory, aka 'Windows WLAN Service Elevation of Privilege Vulnerability'. | 1.2% | — |
| CVE-2025-49708 | CRIT 9.9 | microsoft windows_10_1809 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network. | 1.2% | — |
| CVE-2025-54097 | MED 6.5 | microsoft windows_server_2008 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.2% | — |
| CVE-2025-54096 | MED 6.5 | microsoft windows_server_2008 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.2% | — |
| CVE-2025-54095 | MED 6.5 | microsoft windows_server_2008 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.2% | — |
| CVE-2025-53806 | MED 6.5 | microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.2% | — |
| CVE-2025-53798 | MED 6.5 | microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.2% | — |