56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-49123 | HIGH 8.1 | microsoft windows_10_1809 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2024-21329 | HIGH 7.3 | microsoft azure_connected_machine_agent Azure Connected Machine Agent Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2019-1414 | HIGH 7.8 | microsoft visual_studio_code An elevation of privilege vulnerability exists in Visual Studio Code when it exposes a debug listener to users of a local computer, aka 'Visual Studio Code Elevation of Privilege Vulnerability'. | 1.1% | — |
| CVE-2019-1320 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1322, CVE-2019-1340. | 1.1% | — |
| CVE-2026-20922 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 1.1% | — |
| CVE-2026-20854 | HIGH 7.5 | microsoft windows_11_24h2 Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2023-21740 | HIGH 7.8 | microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-36558 | MED 6.2 | microsoft .net ASP.NET Core Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2026-54130 | CRIT 9.8 | microsoft 365_copilot Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2023-21548 | HIGH 8.1 | microsoft windows_10_1607 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-21535 | HIGH 8.1 | microsoft windows_10_1607 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2021-26889 | HIGH 7.8 | microsoft windows_10 Windows Update Stack Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2017-8466 | HIGH 7.8 | microsoft windows_10 Windows Cursor in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows improper elevation of privilege, aka "Windows Cursor Elevation of Privilege Vulnerability". | 1.1% | — |
| CVE-2024-49071 | MED 6.5 | microsoft defender_for_endpoint Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2025-62456 | HIGH 8.8 | microsoft windows_11_23h2 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2022-34302 | MED 6.7 | horizondatasys uefi_bootloader A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace | 1.1% | — |
| CVE-2025-26687 | HIGH 7.5 | microsoft 365_copilot Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2025-21393 | MED 6.3 | microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability | 1.1% | — |
| CVE-2021-43221 | MED 4.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2021-34483 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2026-54108 | MED 6.5 | microsoft sharepoint_server External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 1.1% | — |
| CVE-2025-53767 | CRIT 10.0 | microsoft azure_openai Azure OpenAI Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2024-49120 | HIGH 8.1 | microsoft windows_server_2012 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-23266 | HIGH 7.8 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2020-1250 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit thi | 1.1% | — |