IT
56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-17099 MED 6.8 microsoft windows_10 Windows Lock Screen Security Feature Bypass Vulnerability 1.0%
CVE-2026-34401 MED 6.5 microsoft xml_notepad XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, XML Notepad does not disable DTD processing by default which means external entities are resolved automatically. 1.0%
CVE-2025-58729 MED 6.5 microsoft windows_10_1507 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. 1.0%
CVE-2025-33066 HIGH 8.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2023-36896 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 1.0%
CVE-2023-35372 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 1.0%
CVE-2023-35371 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 1.0%
CVE-2022-37991 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 1.0%
CVE-2022-37988 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 1.0%
CVE-2025-32710 HIGH 8.1 microsoft windows_server_2008 Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2025-65037 CRIT 10.0 microsoft azure_container_apps Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2024-38010 HIGH 8.0 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 1.0%
CVE-2024-37989 HIGH 8.0 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 1.0%
CVE-2024-37988 HIGH 8.0 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 1.0%
CVE-2024-37986 HIGH 8.0 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 1.0%
CVE-2024-37974 HIGH 8.0 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 1.0%
CVE-2024-37972 HIGH 8.0 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 1.0%
CVE-2020-17074 HIGH 7.8 microsoft windows_10 Windows Update Orchestrator Service Elevation of Privilege Vulnerability 1.0%
CVE-2020-16995 HIGH 7.8 microsoft network_watcher_agent <p>An elevation of privilege vulnerability exists in Network Watcher Agent virtual machine extension for Linux. An attacker who successfully exploited this vulnerability could execute code with elevated privileges.</p> <p>To exploit this vulnerability, an atta 1.0%
CVE-2026-62815 CRIT 9.8 microsoft windows_11_23h2 Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2023-36420 HIGH 7.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 1.0%
CVE-2023-36417 HIGH 7.8 microsoft ole_db_driver_for_sql_server Microsoft SQL OLE DB Remote Code Execution Vulnerability 1.0%
CVE-2025-64670 MED 6.5 microsoft windows_10_21h2 Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network. 1.0%
CVE-2024-49038 CRIT 9.3 microsoft copilot_studio Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network. 1.0%
CVE-2021-28326 MED 5.5 microsoft windows_10 Windows AppX Deployment Server Denial of Service Vulnerability 1.0%