IT
56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-16943 MED 6.5 microsoft dynamics_365 <p>An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Commerce. An unauthenticated attacker who successfully exploited this vulnerability could update data without proper authorization.</p> <p>To exploit the vulnerability, an attacker wou 1.1%
CVE-2026-20856 HIGH 8.1 microsoft windows_10_1607 Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network. 1.1%
CVE-2024-26220 MED 5.0 microsoft windows_10_1507 Windows Mobile Hotspot Information Disclosure Vulnerability 1.1%
CVE-2024-21394 HIGH 7.6 microsoft dynamics_365 Dynamics 365 Field Service Spoofing Vulnerability 1.1%
CVE-2022-21969 CRIT 9.0 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 1.1%
CVE-2020-0791 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0898. 1.1%
CVE-2018-0788 HIGH 7.0 microsoft windows_7 The Windows Adobe Type Manager Font Driver (Atmfd.dll) in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 and R2 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka 1.1%
CVE-2026-32093 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally. 1.1%
CVE-2025-55698 HIGH 7.7 microsoft windows_11_24h2 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network. 1.1%
CVE-2025-29969 HIGH 7.5 microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network. 1.1%
CVE-2024-38187 HIGH 7.8 microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 1.1%
CVE-2024-38185 HIGH 7.8 microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 1.1%
CVE-2024-30086 HIGH 7.8 microsoft windows_10_1507 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability 1.1%
CVE-2023-35308 MED 6.5 microsoft windows_10_1507 Windows MSHTML Platform Security Feature Bypass Vulnerability 1.1%
CVE-2020-17071 MED 5.5 microsoft windows_10 Windows Delivery Optimization Information Disclosure Vulnerability 1.1%
CVE-2020-17069 MED 5.5 microsoft windows_10 Windows NDIS Information Disclosure Vulnerability 1.1%
CVE-2023-21705 HIGH 8.8 microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability 1.1%
CVE-2020-1070 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An 1.1%
CVE-2026-62898 HIGH 7.5 microsoft .net Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. 1.1%
CVE-2023-36710 HIGH 7.8 microsoft windows_10_1507 Windows Media Foundation Core Remote Code Execution Vulnerability 1.1%
CVE-2022-41120 HIGH 7.8 microsoft windows_sysmon Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability 1.1%
CVE-2024-38262 HIGH 7.5 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability 1.1%
CVE-2022-33632 MED 4.7 microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability 1.1%
CVE-2025-21366 HIGH 7.8 microsoft 365_apps Microsoft Access Remote Code Execution Vulnerability 1.1%
CVE-2022-41032 HIGH 7.8 fedoraproject fedora NuGet Client Elevation of Privilege Vulnerability 1.1%