IT
57.023 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-53734 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. 0.4%
CVE-2023-24946 HIGH 7.8 microsoft windows_10_1507 Windows Backup Service Elevation of Privilege Vulnerability 0.4%
CVE-2026-49177 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-32085 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally. 0.4%
CVE-2025-48818 MED 6.8 microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.4%
CVE-2025-29816 HIGH 7.5 microsoft 365_apps Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network. 0.4%
CVE-2022-33644 HIGH 7.0 microsoft windows_10 Xbox Live Save Service Elevation of Privilege Vulnerability 0.4%
CVE-2026-72984 HIGH 8.8 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.4%
CVE-2026-69555 CRIT 10.0 microsoft azure_arc Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. 0.4%
CVE-2026-65807 HIGH 8.8 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. 0.4%
CVE-2026-58283 HIGH 8.1 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2025-59198 MED 5.0 microsoft windows_10_1507 Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally. 0.4%
CVE-2025-53147 HIGH 7.0 microsoft windows_10_1507 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-48821 HIGH 7.1 microsoft windows_10_1507 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network. 0.4%
CVE-2025-21325 HIGH 7.8 microsoft windows_10_21h2 Windows Secure Kernel Mode Elevation of Privilege Vulnerability 0.4%
CVE-2022-24525 HIGH 7.0 microsoft windows_10 Windows Update Stack Elevation of Privilege Vulnerability 0.4%
CVE-2026-47292 HIGH 7.8 microsoft visual_studio_code Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally. 0.4%
CVE-2026-32171 HIGH 8.8 microsoft azure_logic_apps Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. 0.4%
CVE-2026-26179 HIGH 7.8 microsoft windows_11_23h2 Double free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-30393 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-65657 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-26117 HIGH 7.8 microsoft arc_enabled_servers_azure_connected_machine_agent Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-53726 HIGH 7.8 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-53724 HIGH 7.8 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-53152 HIGH 7.8 microsoft windows_10_1507 Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally. 0.4%