56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-28313 | HIGH 7.8 | microsoft visual_studio Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-0689 | MED 6.7 | microsoft windows_10 A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security Feature Bypass Vulnerability'. | 1.0% | — |
| CVE-2019-1142 | MED 5.5 | microsoft .net_framework An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka '.NET Framework Elevation of Privilege Vulnerability'. | 1.0% | — |
| CVE-2025-62214 | MED 6.7 | microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally. | 1.0% | — |
| CVE-2023-38140 | MED 5.5 | microsoft windows_10_1607 Windows Kernel Information Disclosure Vulnerability | 1.0% | — |
| CVE-2023-36895 | HIGH 7.8 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2026-58529 | HIGH 7.1 | microsoft windows_11_26h1 Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-57991 | HIGH 7.4 | microsoft edge_chromium Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2025-64672 | HIGH 8.8 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 1.0% | — |
| CVE-2025-64666 | HIGH 7.5 | microsoft exchange_server Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2025-29791 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | 1.0% | — |
| CVE-2025-27752 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 1.0% | — |
| CVE-2024-26181 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Denial of Service Vulnerability | 1.0% | — |
| CVE-2020-17097 | LOW 3.3 | microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-1011 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows System Assessment Tool improperly handles file operations, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0934, CVE-2020-0983, CVE-2020-1009, CVE-2020-1015 | 1.0% | — |
| CVE-2020-1009 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Microsoft Store Install Service handles file operations in protected locations, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0934, CVE-2020-0983, CVE- | 1.0% | — |
| CVE-2026-48567 | CRIT 10.0 | microsoft azure_horizondb Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2024-49088 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2024-26248 | HIGH 7.5 | microsoft windows_10_1507 Windows Kerberos Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2023-36730 | HIGH 7.8 | microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-35348 | MED 6.5 | microsoft windows_server_2016 Active Directory Federation Service Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2020-17126 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 1.0% | — |
| CVE-2020-19725 | HIGH 7.8 | microsoft z3 There is a use-after-free vulnerability in file pdd_simplifier.cpp in Z3 before 4.8.8. It occurs when the solver attempt to simplify the constraints and causes unexpected memory access. It can cause segmentation faults or arbitrary code execution. | 1.0% | — |
| CVE-2023-36881 | MED 4.5 | microsoft azure_hdinsight Azure Apache Ambari Spoofing Vulnerability | 1.0% | — |
| CVE-2023-36877 | MED 4.5 | microsoft azure_hdinsight Azure Apache Oozie Spoofing Vulnerability | 1.0% | — |