IT
57.023 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-62453 MED 5.0 microsoft visual_studio_code Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally. 0.4%
CVE-2026-21251 HIGH 7.8 microsoft windows_server_2016 Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-21246 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-21245 HIGH 7.8 microsoft windows_11_24h2 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-21239 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-21236 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-21232 HIGH 7.8 microsoft windows_11_23h2 Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-26636 MED 5.5 microsoft windows_11_24h2 Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally. 0.4%
CVE-2023-36565 HIGH 7.0 microsoft 365_copilot Microsoft Office Graphics Elevation of Privilege Vulnerability 0.4%
CVE-2026-32181 MED 5.5 microsoft windows_10_21h2 Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally. 0.4%
CVE-2026-26178 HIGH 8.8 microsoft windows_10_1607 Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate privileges locally. 0.4%
CVE-2026-26109 HIGH 8.4 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-62557 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-21522 MED 6.7 microsoft confcom Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-20962 MED 4.4 microsoft windows_10_1809 Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally. 0.4%
CVE-2025-60703 HIGH 7.8 microsoft windows_10_1607 Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-59201 HIGH 7.8 microsoft windows_10_1507 Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-56167 HIGH 8.5 microsoft azure_ai_search Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. 0.4%
CVE-2026-20956 HIGH 7.8 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-62216 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-62205 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-59292 HIGH 8.2 microsoft azure_compute_gallery External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-59291 HIGH 8.2 microsoft azure_compute_gallery External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-55317 HIGH 7.8 microsoft autoupdate Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-55245 HIGH 7.8 microsoft xbox_gaming_services Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally. 0.4%