IT
56.932 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-50678 MED 6.6 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-62896 CRIT 9.6 microsoft teams Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-49176 HIGH 7.8 microsoft windows_10_1607 Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2023-36769 MED 4.6 microsoft onenote Microsoft OneNote Spoofing Vulnerability 0.5%
CVE-2026-20939 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-49682 HIGH 7.3 microsoft windows_10_21h2 Use after free in Windows Media allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2026-50364 HIGH 7.3 microsoft windows_10_21h2 Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2026-20937 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-62720 MED 6.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. 0.5%
CVE-2026-62716 MED 6.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. 0.5%
CVE-2026-62714 MED 6.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. 0.5%
CVE-2026-49794 MED 4.6 microsoft windows_10_1607 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. 0.5%
CVE-2025-62449 MED 6.8 microsoft github_copilot_chat Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally. 0.5%
CVE-2023-24930 HIGH 7.8 microsoft onedrive Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability 0.5%
CVE-2022-21975 MED 4.7 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 0.5%
CVE-2026-70314 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-20957 HIGH 7.8 microsoft 365_apps Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-20938 HIGH 7.8 microsoft windows_11_23h2 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2026-20870 HIGH 7.8 microsoft windows_11_24h2 Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-60706 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-59513 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-59190 MED 5.5 microsoft windows_10_1507 Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally. 0.5%
CVE-2025-54109 MED 6.7 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-54094 MED 6.7 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-53810 MED 6.7 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. 0.5%