IT
56.864 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-56157 MED 5.4 microsoft sharepoint_server Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.5%
CVE-2026-56193 HIGH 7.1 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-25190 HIGH 7.8 microsoft windows_10_1607 Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-62470 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-59251 HIGH 7.6 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 0.5%
CVE-2026-47632 HIGH 8.8 microsoft azure_connected_machine_agent Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network. 0.5%
CVE-2026-41612 MED 5.5 microsoft live_preview Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2025-32705 HIGH 7.8 microsoft 365_apps Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-56163 CRIT 10.0 microsoft azure_kubernetes_service Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-47280 CRIT 10.0 microsoft azure_resource_manager Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-42822 CRIT 10.0 microsoft azure_local Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2025-59233 HIGH 7.8 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-59231 HIGH 7.8 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5%
CVE-2023-35342 HIGH 7.8 microsoft windows_10_1507 Windows Image Acquisition Elevation of Privilege Vulnerability 0.5%
CVE-2023-35312 HIGH 7.8 microsoft windows_10_1507 Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability 0.5%
CVE-2023-21755 HIGH 7.8 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0.5%
CVE-2022-44680 HIGH 7.8 microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability 0.5%
CVE-2022-44677 HIGH 7.8 microsoft windows_10 Windows Projected File System Elevation of Privilege Vulnerability 0.5%
CVE-2022-41094 HIGH 7.8 microsoft windows_10_1607 Windows Hyper-V Elevation of Privilege Vulnerability 0.5%
CVE-2021-34537 HIGH 7.8 microsoft windows_10 Windows Bluetooth Driver Elevation of Privilege Vulnerability 0.5%
CVE-2026-26108 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-20920 HIGH 7.8 microsoft windows_11_23h2 Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2026-20810 HIGH 7.8 microsoft windows_10_1809 Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-55699 MED 5.5 microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-49736 MED 4.3 microsoft edge The ui performs the wrong action in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. 0.5%