IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-36973 HIGH 7.8 microsoft windows_10 Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability 0.5%
CVE-2021-36966 HIGH 7.8 microsoft windows_10 Windows Subsystem for Linux Elevation of Privilege Vulnerability 0.5%
CVE-2021-36964 HIGH 7.8 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0.5%
CVE-2021-36954 HIGH 8.8 microsoft windows_10 Windows Bind Filter Driver Elevation of Privilege Vulnerability 0.5%
CVE-2026-44812 HIGH 7.8 microsoft excel Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-44803 HIGH 7.8 microsoft excel Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-33113 MED 5.4 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2026-32223 MED 6.8 microsoft windows_11_24h2 Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. 0.5%
CVE-2023-21730 HIGH 7.8 microsoft windows_10_1607 Microsoft Cryptographic Services Elevation of Privilege Vulnerability 0.5%
CVE-2022-44681 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.5%
CVE-2026-45635 HIGH 8.1 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-45599 HIGH 8.1 microsoft windows_10_1607 Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-41613 HIGH 8.8 microsoft visual_studio_code Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2025-53761 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-53741 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-53738 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-29829 MED 5.5 microsoft windows_10_1507 Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally. 0.5%
CVE-2024-21439 HIGH 7.0 microsoft windows_10_1507 Windows Telephony Server Elevation of Privilege Vulnerability 0.5%
CVE-2023-35353 HIGH 7.8 microsoft windows_10_1607 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability 0.5%
CVE-2023-35326 MED 5.5 microsoft windows_10_1809 Windows CDP User Components Information Disclosure Vulnerability 0.5%
CVE-2023-35324 MED 5.5 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 0.5%
CVE-2023-35306 MED 5.5 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 0.5%
CVE-2023-32085 MED 5.5 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 0.5%
CVE-2023-32040 MED 5.5 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 0.5%
CVE-2023-32039 MED 5.5 microsoft windows_10_1507 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability 0.5%