IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-47972 HIGH 8.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2025-21287 HIGH 7.8 microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability 0.5%
CVE-2023-36724 MED 5.5 microsoft windows_10_1507 Windows Power Management Service Information Disclosure Vulnerability 0.5%
CVE-2023-29359 HIGH 7.8 microsoft windows_10_1507 GDI Elevation of Privilege Vulnerability 0.5%
CVE-2026-66321 HIGH 7.4 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-21247 HIGH 7.3 microsoft windows_10_1607 Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. 0.5%
CVE-2025-26679 HIGH 7.8 microsoft windows_10_1507 Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2022-22016 HIGH 7.0 microsoft windows_10 Windows PlayToManager Elevation of Privilege Vulnerability 0.5%
CVE-2025-26681 MED 6.7 microsoft windows_10_21h2 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2023-24934 MED 6.2 microsoft malware_protection_platform Microsoft Defender Security Feature Bypass Vulnerability 0.5%
CVE-2026-62900 MED 5.9 microsoft .net Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. 0.5%
CVE-2025-62556 HIGH 7.8 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-26688 HIGH 7.8 microsoft windows_10_1507 Stack-based buffer overflow in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2024-43644 HIGH 7.8 microsoft windows_10_1507 Windows Client-Side Caching Elevation of Privilege Vulnerability 0.5%
CVE-2023-32052 MED 5.4 microsoft power_apps Microsoft Power Apps (online) Spoofing Vulnerability 0.5%
CVE-2026-63512 MED 6.5 microsoft sharepoint_server Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network. 0.5%
CVE-2026-20948 HIGH 7.8 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-30383 HIGH 7.8 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-30381 HIGH 7.8 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-30379 HIGH 7.8 microsoft 365_apps Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-33074 HIGH 7.5 microsoft azure_functions Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network. 0.5%
CVE-2022-35749 HIGH 7.8 microsoft windows_10_1507 Windows Digital Media Receiver Elevation of Privilege Vulnerability 0.5%
CVE-2022-35746 HIGH 7.8 microsoft windows_10_1507 Windows Digital Media Receiver Elevation of Privilege Vulnerability 0.5%
CVE-2022-29106 HIGH 7.0 microsoft windows_10 Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability 0.5%
CVE-2022-26939 HIGH 7.0 microsoft windows_server Storage Spaces Direct Elevation of Privilege Vulnerability 0.5%