IT
56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-43482 MED 6.5 microsoft outlook Microsoft Outlook for iOS Information Disclosure Vulnerability 1.1%
CVE-2017-0193 HIGH 7.8 microsoft windows_10 Windows Hyper-V in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to gain elevated privileges on a target 1.1%
CVE-2023-36024 HIGH 7.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.1%
CVE-2026-26115 HIGH 8.8 microsoft sql_server_2016 Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network. 1.1%
CVE-2025-47966 CRIT 9.8 microsoft power_automate_for_desktop Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network. 1.1%
CVE-2024-43604 MED 5.7 microsoft outlook Outlook for Android Elevation of Privilege Vulnerability 1.1%
CVE-2023-21717 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Elevation of Privilege Vulnerability 1.1%
CVE-2022-41066 MED 4.4 microsoft dynamics_365_business_central_2019 Microsoft Dynamics Business Central Information Disclosure Vulnerability 1.1%
CVE-2021-28316 MED 4.2 microsoft windows_10 Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability 1.1%
CVE-2024-43550 HIGH 7.4 microsoft windows_10_1507 Windows Secure Channel Spoofing Vulnerability 1.1%
CVE-2022-21887 HIGH 7.0 microsoft windows_11 Win32k Elevation of Privilege Vulnerability 1.1%
CVE-2019-1341 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when umpo.dll of the Power Service, improperly handles a Registry Restore Key function, aka 'Windows Power Service Elevation of Privilege Vulnerability'. 1.1%
CVE-2023-38160 MED 5.5 microsoft windows_10_1507 Windows TCP/IP Information Disclosure Vulnerability 1.1%
CVE-2022-41118 HIGH 7.5 microsoft windows_10 Windows Scripting Languages Remote Code Execution Vulnerability 1.1%
CVE-2022-38004 HIGH 7.8 microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability 1.1%
CVE-2020-1115 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the <a href="https://technet.microsoft.com/library/security/dn848375.aspx#CLFS">Windows Common Log File System (CLFS)</a> driver improperly handles objects in memory. An attacker who successfully exploited 1.1%
CVE-2022-41057 HIGH 7.8 microsoft windows_10 Windows HTTP.sys Elevation of Privilege Vulnerability 1.1%
CVE-2022-21906 MED 5.5 microsoft windows_10 Windows Defender Application Control Security Feature Bypass Vulnerability 1.1%
CVE-2025-53727 HIGH 8.8 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 1.1%
CVE-2024-43574 HIGH 8.3 microsoft windows_10_21h2 Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability 1.1%
CVE-2023-29334 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 1.1%
CVE-2021-38672 HIGH 8.0 microsoft windows_11 Windows Hyper-V Remote Code Execution Vulnerability 1.1%
CVE-2025-29792 HIGH 7.3 microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. 1.1%
CVE-2022-21918 MED 6.5 microsoft windows_10 DirectX Graphics Kernel File Denial of Service Vulnerability 1.1%
CVE-2024-49132 HIGH 8.1 microsoft windows_10_1809 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.1%