IT
57.023 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-50153 HIGH 7.8 microsoft windows_10_1507 Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-49761 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2024-43590 HIGH 7.8 microsoft visual_c\+\+_redistributable Visual C++ Redistributable Installer Elevation of Privilege Vulnerability 0.4%
CVE-2025-55679 MED 5.1 microsoft windows_10_1809 Improper input validation in Windows Kernel allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2024-49049 HIGH 7.1 microsoft remote_ssh Visual Studio Code Remote Extension Elevation of Privilege Vulnerability 0.4%
CVE-2026-61352 HIGH 7.5 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.4%
CVE-2026-45649 HIGH 7.1 microsoft excel Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally. 0.4%
CVE-2023-35328 HIGH 7.8 microsoft windows_10_1507 Windows Transaction Manager Elevation of Privilege Vulnerability 0.4%
CVE-2023-35305 HIGH 7.8 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0.4%
CVE-2023-35304 HIGH 7.8 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0.4%
CVE-2023-21756 HIGH 7.8 microsoft windows_10_1507 Windows Win32k Elevation of Privilege Vulnerability 0.4%
CVE-2026-41086 HIGH 8.8 microsoft windows_admin_center Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. 0.4%
CVE-2026-40403 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally. 0.4%
CVE-2025-59280 LOW 3.1 microsoft windows_10_1507 Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network. 0.4%
CVE-2024-38158 HIGH 7.0 microsoft azure_iot_hub_device_client_sdk Azure IoT SDK Remote Code Execution Vulnerability 0.4%
CVE-2024-38136 HIGH 7.0 microsoft windows_10_1809 Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability 0.4%
CVE-2026-69851 CRIT 9.9 microsoft entra_id Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. 0.4%
CVE-2026-35430 HIGH 8.8 microsoft azure_privileged_identity_management Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network. 0.4%
CVE-2025-33067 HIGH 8.4 microsoft windows_10_1507 Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally. 0.4%
CVE-2026-70348 MED 5.5 microsoft windows_11_24h2 Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally. 0.4%
CVE-2025-62223 MED 4.3 microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2024-38137 HIGH 7.0 microsoft windows_10_21h2 Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability 0.4%
CVE-2023-32009 HIGH 8.8 microsoft windows_10_1607 Windows Collaborative Translation Framework Elevation of Privilege Vulnerability 0.4%
CVE-2025-62554 HIGH 8.4 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-45595 MED 5.4 microsoft windows_10_1607 Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network. 0.4%