IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-42319 MED 4.7 microsoft visual_studio_2017 Visual Studio Elevation of Privilege Vulnerability 0.5%
CVE-2021-24092 HIGH 7.8 microsoft endpoint_protection Microsoft Defender Elevation of Privilege Vulnerability 0.5%
CVE-2026-65789 HIGH 8.1 microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-20819 MED 5.5 microsoft windows_11_23h2 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. 0.5%
CVE-2023-28235 MED 6.8 microsoft windows_10_1809 Windows Lock Screen Security Feature Bypass Vulnerability 0.5%
CVE-2021-43239 HIGH 7.1 microsoft windows_10 Windows Recovery Environment Agent Elevation of Privilege Vulnerability 0.5%
CVE-2021-42312 HIGH 7.8 microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability 0.5%
CVE-2021-36968 HIGH 7.8 microsoft windows_7 Windows DNS Elevation of Privilege Vulnerability 0.5%
CVE-2026-62820 HIGH 8.1 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-26113 HIGH 8.4 microsoft 365_apps Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-29955 MED 6.2 microsoft windows_11_24h2 Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally. 0.5%
CVE-2023-38175 HIGH 7.8 microsoft windows_defender Microsoft Windows Defender Elevation of Privilege Vulnerability 0.5%
CVE-2023-35364 HIGH 8.8 microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability 0.5%
CVE-2023-28299 MED 5.5 microsoft visual_studio_2017 Visual Studio Spoofing Vulnerability 0.5%
CVE-2022-23276 HIGH 7.8 microsoft sql_server SQL Server for Linux Containers Elevation of Privilege Vulnerability 0.5%
CVE-2021-40467 HIGH 7.8 microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability 0.5%
CVE-2026-50460 HIGH 8.1 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-50365 HIGH 8.0 microsoft windows_10_1607 Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network. 0.5%
CVE-2026-42900 HIGH 8.1 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-32226 MED 5.9 microsoft .net_framework Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network. 0.5%
CVE-2024-43646 MED 6.7 microsoft windows_10_1607 Windows Secure Kernel Mode Elevation of Privilege Vulnerability 0.5%
CVE-2024-43645 MED 6.7 microsoft windows_10_1507 Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability 0.5%
CVE-2024-43631 MED 6.7 microsoft windows_10_21h2 Windows Secure Kernel Mode Elevation of Privilege Vulnerability 0.5%
CVE-2026-68782 CRIT 9.9 microsoft azure_sql_database Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-57084 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally. 0.5%