56.801 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-50497 | MED 6.5 | microsoft windows_10_1607 Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-50445 | MED 6.5 | microsoft windows_10_1607 Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-50376 | MED 6.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-57979 | MED 6.5 | microsoft windows_10_1607 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-55003 | MED 6.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-56646 | MED 6.5 | microsoft edge_chromium Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2026-50519 | MED 6.5 | microsoft github_copilot_chat Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-41104 | CRIT 10.0 | microsoft planetary_computer Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2025-30399 | HIGH 7.5 | microsoft .net Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2025-30390 | CRIT 9.9 | microsoft azure_machine_learning Improper authorization in Azure allows an authorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2023-29344 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2020-0783 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0781. | 0.9% | — |
| CVE-2020-0781 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0783. | 0.9% | — |
| CVE-2020-0641 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerabi | 0.9% | — |
| CVE-2026-47284 | MED 6.5 | microsoft visual_studio_code Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2025-49657 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2025-21198 | CRIT 9.0 | microsoft hpc_pack_2016 Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-49087 | MED 4.6 | microsoft windows_10_1809 Windows Mobile Broadband Driver Information Disclosure Vulnerability | 0.9% | — |
| CVE-2023-36591 | HIGH 7.3 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2020-17034 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-17031 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-17027 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-1333 | MED 6.7 | microsoft windows_10 An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points, aka 'Group Policy Services Policy Processing Elevation of Privilege Vulnerability'. | 0.9% | — |
| CVE-2024-26174 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 0.9% | — |
| CVE-2022-29149 | HIGH 7.8 | microsoft azure_automation_state_configuration Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | 0.9% | — |