IT
57.023 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-26107 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-59222 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-29833 HIGH 7.7 microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-42993 HIGH 7.5 microsoft windows_10_21h2 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.4%
CVE-2025-48815 HIGH 7.8 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows SSDP Service allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2024-49084 HIGH 7.0 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.4%
CVE-2023-21561 HIGH 7.8 microsoft windows_10_1607 Microsoft Cryptographic Services Elevation of Privilege Vulnerability 0.4%
CVE-2023-21551 HIGH 7.8 microsoft windows_10_1809 Microsoft Cryptographic Services Elevation of Privilege Vulnerability 0.4%
CVE-2026-26133 HIGH 7.1 microsoft 365_copilot AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. 0.4%
CVE-2025-48809 MED 5.5 microsoft windows_11_24h2 Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-48565 HIGH 7.8 microsoft windows_narrator_braille Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-27478 HIGH 7.0 microsoft windows_10_1507 Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2024-38179 HIGH 8.8 microsoft azure_stack_hci Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability 0.4%
CVE-2023-36721 HIGH 7.0 microsoft windows_10_1809 Windows Error Reporting Service Elevation of Privilege Vulnerability 0.4%
CVE-2026-58290 HIGH 7.5 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.4%
CVE-2026-21508 HIGH 7.0 microsoft windows_10_1607 Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-32726 MED 6.8 microsoft visual_studio_code Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-20928 MED 4.6 microsoft windows_10_1607 Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack. 0.4%
CVE-2026-24288 MED 6.8 microsoft windows_10_21h2 Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical attack. 0.4%
CVE-2025-55680 HIGH 7.8 microsoft windows_10_1809 Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-53725 HIGH 7.8 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-53154 HIGH 7.8 microsoft windows_10_1507 Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-53151 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-53141 HIGH 7.8 microsoft windows_10_1507 Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-50155 HIGH 7.8 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.4%