IT
57.044 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.482 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-54115 HIGH 7.0 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2022-26808 HIGH 7.0 microsoft windows_10 Windows File Explorer Elevation of Privilege Vulnerability 0.4%
CVE-2026-58643 MED 6.1 microsoft windows_admin_center Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2026-58524 MED 5.4 microsoft edge_chromium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2026-58298 HIGH 7.2 microsoft edge_chromium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2026-45655 MED 5.3 microsoft windows_10_1607 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.4%
CVE-2025-55321 CRIT 9.3 microsoft azure_monitor Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2024-38208 MED 6.1 microsoft edge Microsoft Edge for Android Spoofing Vulnerability 0.4%
CVE-2024-38156 MED 6.1 microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.4%
CVE-2026-69306 HIGH 8.2 microsoft visual_studio_code Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. 0.4%
CVE-2026-64922 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.4%
CVE-2026-64916 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.4%
CVE-2026-64902 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.4%
CVE-2026-64897 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.4%
CVE-2026-50428 HIGH 7.1 microsoft windows_11_26h1 Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. 0.4%
CVE-2025-49707 HIGH 7.9 microsoft dcadsv5-series_azure_vm_firmware Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally. 0.4%
CVE-2026-45636 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-32188 HIGH 7.1 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-26156 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-23657 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-60718 HIGH 7.8 microsoft windows_11_24h2 Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2023-35299 HIGH 7.8 microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 0.4%
CVE-2022-29113 HIGH 7.8 microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability 0.4%
CVE-2026-54999 HIGH 8.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network. 0.4%
CVE-2025-54103 HIGH 7.4 microsoft windows_10_21h2 Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally. 0.4%