56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-57083 | MED 5.5 | microsoft windows_10_1607 Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-56195 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-55138 | MED 5.5 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-55057 | MED 5.5 | microsoft 365_apps Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-55046 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-55042 | MED 5.5 | microsoft 365_apps Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-50408 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-48580 | MED 5.5 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-58297 | HIGH 7.1 | microsoft edge_chromium Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2026-58296 | HIGH 7.1 | microsoft edge_chromium Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2024-21445 | HIGH 7.0 | microsoft windows_10_21h2 Windows USB Print Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-69558 | HIGH 8.6 | microsoft partner_center Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2026-66800 | HIGH 8.6 | microsoft azure_data_factory Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2025-49664 | MED 5.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Host allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-47173 | HIGH 7.8 | microsoft 365_apps Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-21271 | HIGH 7.8 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-30099 | HIGH 7.0 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-21336 | LOW 2.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.5% | — |
| CVE-2026-26137 | CRIT 9.9 | microsoft 365_copilot_chat Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-62872 | HIGH 8.8 | microsoft .net_framework Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2025-55332 | MED 6.1 | microsoft windows_10_1809 Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0.5% | — |
| CVE-2025-55330 | MED 6.1 | microsoft windows_11_22h2 Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0.5% | — |
| CVE-2024-43584 | HIGH 7.7 | microsoft windows_11_21h2 Windows Scripting Engine Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2022-24480 | MED 6.3 | microsoft outlook Outlook for Android Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-62814 | MED 6.5 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | 0.5% | — |