IT
57.023 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-28262 HIGH 7.8 microsoft visual_studio_2019 Visual Studio Elevation of Privilege Vulnerability 0.4%
CVE-2026-62917 MED 4.6 microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.4%
CVE-2026-54123 MED 5.5 microsoft defender_for_endpoint Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-50668 MED 6.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack. 0.4%
CVE-2026-50492 MED 6.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack. 0.4%
CVE-2026-54132 MED 6.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. 0.4%
CVE-2026-50299 MED 6.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack. 0.4%
CVE-2026-50298 MED 6.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack. 0.4%
CVE-2026-49168 MED 6.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack. 0.4%
CVE-2026-45458 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-45456 HIGH 8.4 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-42904 CRIT 9.6 microsoft windows_10_21h2 Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. 0.4%
CVE-2024-49097 HIGH 7.0 microsoft windows_10_1809 Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability 0.4%
CVE-2024-49095 HIGH 7.0 microsoft windows_10_1809 Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability 0.4%
CVE-2026-45485 LOW 3.3 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-42831 HIGH 7.8 microsoft 365_copilot Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-21199 MED 6.7 microsoft azure_agent Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-32218 MED 5.5 microsoft windows_10_21h2 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. 0.4%
CVE-2025-59209 MED 5.5 microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally. 0.4%
CVE-2025-49684 MED 5.5 microsoft windows_10_1507 Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally. 0.4%
CVE-2023-36568 HIGH 7.0 microsoft 365_apps Microsoft Office Click-To-Run Elevation of Privilege Vulnerability 0.4%
CVE-2023-35337 HIGH 7.8 microsoft windows_10_21h2 Win32k Elevation of Privilege Vulnerability 0.4%
CVE-2023-23381 HIGH 7.8 microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability 0.4%
CVE-2026-62836 HIGH 8.7 microsoft azure_sql_managed_instance Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. 0.4%
CVE-2026-58522 MED 6.8 microsoft edge_chromium Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. 0.4%