IT
56.864 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-55226 MED 6.7 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally. 0.5%
CVE-2023-36698 MED 4.4 microsoft windows_10_1809 Windows Kernel Security Feature Bypass Vulnerability 0.5%
CVE-2026-62735 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2023-21680 HIGH 7.8 microsoft windows_10_1607 Windows Win32k Elevation of Privilege Vulnerability 0.5%
CVE-2026-45496 MED 5.5 microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0.5%
CVE-2026-45583 HIGH 7.5 microsoft exchange_server Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-20960 HIGH 8.0 microsoft power_apps Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network. 0.5%
CVE-2025-21370 HIGH 7.8 microsoft windows_11_22h2 Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability 0.5%
CVE-2026-42830 MED 6.5 microsoft azure_monitor_agent Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-49721 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally. 0.5%
CVE-2025-32719 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-24068 MED 5.5 microsoft windows_10_1507 Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2021-42286 HIGH 7.8 microsoft windows_10 Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability 0.5%
CVE-2021-42283 HIGH 8.8 microsoft windows_10 NTFS Elevation of Privilege Vulnerability 0.5%
CVE-2021-41377 HIGH 7.8 microsoft windows_10 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability 0.5%
CVE-2021-41370 HIGH 7.8 microsoft windows_10 NTFS Elevation of Privilege Vulnerability 0.5%
CVE-2021-41367 HIGH 7.8 microsoft windows_10 NTFS Elevation of Privilege Vulnerability 0.5%
CVE-2021-41366 HIGH 7.8 microsoft windows_10 Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability 0.5%
CVE-2021-36957 HIGH 7.8 microsoft windows_10 Windows Desktop Bridge Elevation of Privilege Vulnerability 0.5%
CVE-2026-72971 MED 5.5 microsoft windows_11_26h1 Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally. 0.5%
CVE-2026-55898 MED 6.1 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-42913 HIGH 7.5 microsoft remote_desktop_client Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-33843 CRIT 9.1 microsoft entra_id Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2022-44689 HIGH 7.8 microsoft windows_10 Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability 0.5%
CVE-2026-66309 CRIT 9.1 microsoft azure_sql_database Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. 0.5%