IT
57.023 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-71331 HIGH 8.1 microsoft windows_10_1809 Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-65767 HIGH 8.8 microsoft teams Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network. 0.5%
CVE-2026-25169 MED 6.2 microsoft windows_10_1607 Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service locally. 0.5%
CVE-2025-49711 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5%
CVE-2026-40367 HIGH 8.4 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-53723 HIGH 7.8 microsoft windows_10_1507 Numeric truncation error in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-53155 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-26648 HIGH 7.8 microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2024-38103 MED 5.9 microsoft edge Microsoft Edge (Chromium-based) Information Disclosure Vulnerability 0.5%
CVE-2023-28228 MED 5.5 microsoft windows_10_1507 Windows Spoofing Vulnerability 0.5%
CVE-2026-62918 HIGH 7.5 microsoft teams Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2026-45497 HIGH 7.7 microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network. 0.5%
CVE-2025-59232 HIGH 7.1 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2025-32718 HIGH 7.8 microsoft windows_10_1507 Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-32716 HIGH 7.8 microsoft windows_10_1507 Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-32712 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-21340 MED 5.5 microsoft windows_10_1809 Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability 0.5%
CVE-2025-62465 MED 6.5 microsoft windows_11_23h2 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. 0.5%
CVE-2025-62463 MED 6.5 microsoft windows_10_21h2 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. 0.5%
CVE-2023-28251 MED 5.5 microsoft windows_10_1507 Windows Driver Revocation List Security Feature Bypass Vulnerability 0.5%
CVE-2025-26640 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2019-1416 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists due to a race condition in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'. 0.4%
CVE-2026-61350 MED 4.6 microsoft windows_10_1607 Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. 0.4%
CVE-2026-55026 MED 6.2 microsoft 365_apps Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2025-21360 HIGH 7.8 microsoft autoupdate Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability 0.4%