IT
57.023 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-44699 MED 5.5 microsoft azure_network_watcher_agent Azure Network Watcher Agent Security Feature Bypass Vulnerability 0.4%
CVE-2022-34706 HIGH 7.8 microsoft windows_10 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability 0.4%
CVE-2026-35440 MED 5.5 microsoft 365_apps Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2023-28225 HIGH 7.8 microsoft windows_10_1507 Windows NTLM Elevation of Privilege Vulnerability 0.4%
CVE-2023-21532 HIGH 7.0 microsoft windows_10_1607 Windows GDI Elevation of Privilege Vulnerability 0.4%
CVE-2026-68797 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2025-25004 HIGH 7.3 microsoft powershell Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-54091 HIGH 7.8 microsoft windows_10_1507 Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-25003 HIGH 7.3 microsoft visual_studio_2019 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-24998 HIGH 7.3 microsoft visual_studio_2017 Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-64900 HIGH 7.3 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.4%
CVE-2026-55045 HIGH 8.4 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-58300 MED 6.2 microsoft edge_chromium Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2025-58735 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-58732 HIGH 7.0 microsoft windows_10_1507 Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-54894 HIGH 7.8 microsoft windows_10_1507 Local Security Authority Subsystem Service Elevation of Privilege Vulnerability 0.4%
CVE-2025-54102 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-53801 HIGH 7.8 microsoft windows_10_1507 Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2024-49046 HIGH 7.8 microsoft windows_10_1507 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability 0.4%
CVE-2026-48574 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-45503 HIGH 8.1 microsoft exchange_server Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. 0.4%
CVE-2026-20950 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-20936 MED 4.3 microsoft windows_10_1607 Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack. 0.4%
CVE-2023-23379 HIGH 7.8 microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability 0.4%
CVE-2026-49180 MED 5.5 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. 0.4%