IT
56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-49123 HIGH 8.1 microsoft windows_10_1809 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.1%
CVE-2024-21329 HIGH 7.3 microsoft azure_connected_machine_agent Azure Connected Machine Agent Elevation of Privilege Vulnerability 1.1%
CVE-2019-1414 HIGH 7.8 microsoft visual_studio_code An elevation of privilege vulnerability exists in Visual Studio Code when it exposes a debug listener to users of a local computer, aka 'Visual Studio Code Elevation of Privilege Vulnerability'. 1.1%
CVE-2019-1320 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1322, CVE-2019-1340. 1.1%
CVE-2026-20922 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. 1.1%
CVE-2026-20854 HIGH 7.5 microsoft windows_11_24h2 Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network. 1.1%
CVE-2023-21740 HIGH 7.8 microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability 1.1%
CVE-2023-36558 MED 6.2 microsoft .net ASP.NET Core Security Feature Bypass Vulnerability 1.1%
CVE-2026-54130 CRIT 9.8 microsoft 365_copilot Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. 1.1%
CVE-2023-21548 HIGH 8.1 microsoft windows_10_1607 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 1.1%
CVE-2023-21535 HIGH 8.1 microsoft windows_10_1607 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 1.1%
CVE-2021-26889 HIGH 7.8 microsoft windows_10 Windows Update Stack Elevation of Privilege Vulnerability 1.1%
CVE-2017-8466 HIGH 7.8 microsoft windows_10 Windows Cursor in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows improper elevation of privilege, aka "Windows Cursor Elevation of Privilege Vulnerability". 1.1%
CVE-2024-49071 MED 6.5 microsoft defender_for_endpoint Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network. 1.1%
CVE-2025-62456 HIGH 8.8 microsoft windows_11_23h2 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. 1.1%
CVE-2022-34302 MED 6.7 horizondatasys uefi_bootloader A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace 1.1%
CVE-2025-26687 HIGH 7.5 microsoft 365_copilot Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. 1.1%
CVE-2025-21393 MED 6.3 microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability 1.1%
CVE-2021-43221 MED 4.2 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.1%
CVE-2021-34483 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 1.1%
CVE-2026-54108 MED 6.5 microsoft sharepoint_server External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 1.1%
CVE-2025-53767 CRIT 10.0 microsoft azure_openai Azure OpenAI Elevation of Privilege Vulnerability 1.1%
CVE-2024-49120 HIGH 8.1 microsoft windows_server_2012 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.1%
CVE-2022-23266 HIGH 7.8 microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability 1.1%
CVE-2020-1250 MED 5.5 microsoft windows_10 <p>An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit thi 1.1%