IT
56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-41773 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2020-17020 LOW 3.3 microsoft 365_apps Microsoft Word Security Feature Bypass Vulnerability 1.3%
CVE-2026-42835 HIGH 8.1 microsoft teams Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. 1.3%
CVE-2020-1331 MED 5.4 microsoft system_center_operations_manager A spoofing vulnerability exists when System Center Operations Manager (SCOM) does not properly sanitize a specially crafted web request to an affected SCOM instance, aka 'System Center Operations Manager Spoofing Vulnerability'. 1.3%
CVE-2023-41771 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-41770 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-41769 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-41768 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-41767 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-41765 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-38166 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-23400 HIGH 7.2 microsoft windows_server_2012 Windows DNS Server Remote Code Execution Vulnerability 1.3%
CVE-2021-43220 LOW 3.1 microsoft edge_ios Microsoft Edge for iOS Spoofing Vulnerability 1.3%
CVE-2021-42308 LOW 3.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 1.3%
CVE-2026-50517 CRIT 9.9 microsoft 365_copilot Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. 1.3%
CVE-2021-1672 MED 5.5 microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability 1.3%
CVE-2019-0965 HIGH 7.6 microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a 1.3%
CVE-2020-16921 MED 5.5 microsoft windows_10 <p>An information disclosure vulnerability exists in Text Services Framework when it fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could potentially read data that was not intended to be disclosed. Note t 1.3%
CVE-2020-16919 MED 5.5 microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows Enterprise App Management Service improperly handles certain file operations. An attacker who successfully exploited this vulnerability could read arbitrary files.</p> <p>An attacker with unpri 1.3%
CVE-2026-50330 HIGH 7.5 microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network. 1.3%
CVE-2026-24300 CRIT 9.8 microsoft azure_front_door Azure Front Door Elevation of Privilege Vulnerability 1.3%
CVE-2022-30200 HIGH 7.8 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 1.3%
CVE-2025-26628 HIGH 7.3 microsoft azure_local_cluster Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally. 1.3%
CVE-2024-29050 HIGH 8.4 microsoft windows_10_1507 Windows Cryptographic Services Remote Code Execution Vulnerability 1.3%
CVE-2026-20803 HIGH 7.2 microsoft sql_server_2022 Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network. 1.2%