56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-33062 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-33055 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-42975 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network. | 0.5% | — |
| CVE-2026-26143 | HIGH 7.8 | microsoft powershell Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. | 0.5% | — |
| CVE-2022-33670 | HIGH 7.8 | microsoft windows_10 Windows Partition Management Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-54982 | HIGH 8.8 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. | 0.5% | — |
| CVE-2026-33826 | HIGH 8.0 | microsoft windows_server_2012 Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network. | 0.5% | — |
| CVE-2022-30151 | HIGH 7.0 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-63508 | CRIT 10.0 | microsoft planetary_computer Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-40412 | CRIT 10.0 | microsoft azure_orbital_spatio Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2025-58724 | HIGH 7.8 | microsoft azure_connected_machine_agent Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2023-21760 | HIGH 7.1 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-42285 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-20825 | MED 4.4 | microsoft windows_10_1809 Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-59286 | CRIT 9.3 | microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2025-59272 | CRIT 9.3 | microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally. | 0.5% | — |
| CVE-2025-59252 | CRIT 9.3 | microsoft 365_word_copilot Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2025-24072 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-24059 | HIGH 7.8 | microsoft windows_10_1507 Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-24050 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-24048 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-24046 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2023-36876 | HIGH 7.1 | microsoft windows_server_2008 Reliability Analysis Metrics Calculation (RacTask) Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-72970 | HIGH 8.3 | microsoft edge_chromium Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-35421 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally. | 0.5% | — |