IT
56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-26866 HIGH 7.1 microsoft windows_10 Windows Update Service Elevation of Privilege Vulnerability 1.1%
CVE-2025-27744 HIGH 7.8 microsoft office Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally. 1.1%
CVE-2021-36963 HIGH 7.8 microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability 1.1%
CVE-2017-0156 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists in Windows 7, Windows 8.1, Windows RT 8.1, Windows 10, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 when the Microsoft Graphics Component fails to properly handle ob 1.1%
CVE-2025-50156 MED 5.7 microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. 1.1%
CVE-2025-21259 MED 5.3 microsoft outlook Microsoft Outlook Spoofing Vulnerability 1.1%
CVE-2024-21395 HIGH 8.2 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 1.1%
CVE-2025-21210 MED 4.2 microsoft windows_10_1507 Windows BitLocker Information Disclosure Vulnerability 1.1%
CVE-2025-21186 HIGH 7.8 microsoft 365_apps Microsoft Access Remote Code Execution Vulnerability 1.1%
CVE-2021-26873 HIGH 7.0 microsoft windows_10 Windows User Profile Service Elevation of Privilege Vulnerability 1.1%
CVE-2026-56168 MED 6.5 microsoft windows_10_21h2 Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network. 1.1%
CVE-2026-50366 MED 6.5 microsoft windows_10_1607 Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. 1.1%
CVE-2026-57976 MED 6.5 microsoft windows_10_1607 Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network. 1.1%
CVE-2026-49799 MED 6.5 microsoft windows_10_1607 Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. 1.1%
CVE-2024-30093 HIGH 7.3 microsoft windows_10_1507 Windows Storage Elevation of Privilege Vulnerability 1.1%
CVE-2017-0212 HIGH 7.6 microsoft windows_10 Windows Hyper-V allows an elevation of privilege vulnerability when Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 fail to properly validate vSMB packet data, aka "Windows Hyper-V vSMB Elevation of Privilege Vulnerability". 1.1%
CVE-2023-21560 MED 6.6 microsoft windows_10_1607 Windows Boot Manager Security Feature Bypass Vulnerability 1.1%
CVE-2022-30205 MED 6.6 microsoft windows_10 Windows Group Policy Elevation of Privilege Vulnerability 1.1%
CVE-2021-31187 HIGH 7.8 microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability 1.1%
CVE-2026-33111 HIGH 7.5 microsoft copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. 1.1%
CVE-2026-26129 HIGH 7.5 microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. 1.1%
CVE-2022-30137 MED 6.7 microsoft service_fabric Executive Summary An Elevation of Privilege (EOP) vulnerability has been identified within Service Fabric clusters that run Docker containers. Exploitation of this EOP vulnerability requires an attacker to gain remote code execution within a container. All S 1.1%
CVE-2023-28223 MED 6.6 microsoft windows_server_2008 Windows Domain Name Service Remote Code Execution Vulnerability 1.1%
CVE-2022-23281 MED 5.5 microsoft windows_10 Windows Common Log File System Driver Information Disclosure Vulnerability 1.1%
CVE-2021-1677 MED 5.5 microsoft azure_kubernetes_service Azure Active Directory Pod Identity Spoofing Vulnerability 1.1%