IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-21357 MED 6.7 microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability 0.6%
CVE-2024-38246 HIGH 7.0 microsoft windows_10_21h2 Win32k Elevation of Privilege Vulnerability 0.6%
CVE-2024-28924 MED 6.7 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.6%
CVE-2021-34475 MED 5.4 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 0.6%
CVE-2026-65679 HIGH 8.1 microsoft windows_10_1607 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-26150 HIGH 8.6 microsoft purview_ediscovery Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. 0.6%
CVE-2026-26138 HIGH 8.6 microsoft purview Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. 0.6%
CVE-2023-28298 MED 5.5 microsoft windows_10_1607 Windows Kernel Denial of Service Vulnerability 0.6%
CVE-2026-65770 CRIT 10.0 microsoft azure_managed_instance_for_apache_cassandra Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2025-53739 HIGH 7.8 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-53735 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-50159 HIGH 7.3 microsoft windows_10_1507 Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2024-38248 HIGH 7.0 microsoft windows_10_21h2 Windows Storage Elevation of Privilege Vulnerability 0.6%
CVE-2022-41055 MED 5.5 microsoft windows_10 Windows Human Interface Device Information Disclosure Vulnerability 0.6%
CVE-2025-26631 HIGH 7.3 microsoft visual_studio_code Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-21378 HIGH 7.8 microsoft windows_10_1507 Windows CSC Service Elevation of Privilege Vulnerability 0.6%
CVE-2023-21739 HIGH 7.0 microsoft windows_10_1507 Windows Bluetooth Driver Elevation of Privilege Vulnerability 0.6%
CVE-2021-34460 HIGH 7.8 microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability 0.6%
CVE-2021-34511 HIGH 7.8 microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability 0.6%
CVE-2021-34488 HIGH 7.8 microsoft windows_10 Windows Console Driver Elevation of Privilege Vulnerability 0.6%
CVE-2021-34477 HIGH 7.8 microsoft .net_education_bundle_sdk_install_tool Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability 0.6%
CVE-2026-50481 CRIT 9.9 microsoft azure_active_directory Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. 0.6%
CVE-2026-50528 HIGH 8.2 microsoft .net Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. 0.6%
CVE-2026-26149 CRIT 9.0 microsoft power_apps Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network. 0.6%
CVE-2025-64660 HIGH 8.0 microsoft visual_studio_code Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network. 0.6%