IT
57.044 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.482 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-50170 HIGH 7.8 microsoft windows_10_1809 Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2023-21536 MED 4.7 microsoft windows_10_1809 Event Tracing for Windows Information Disclosure Vulnerability 0.4%
CVE-2022-26827 HIGH 7.0 microsoft windows_10 Windows File Server Resource Management Service Elevation of Privilege Vulnerability 0.4%
CVE-2026-50684 MED 4.8 microsoft windows_10_1607 Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network. 0.4%
CVE-2026-50697 HIGH 7.8 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-26175 MED 4.6 microsoft windows_10_1607 Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack. 0.4%
CVE-2025-62570 HIGH 7.1 microsoft windows_11_24h2 Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally. 0.4%
CVE-2023-32050 HIGH 7.0 microsoft windows_server_2008 Windows Installer Elevation of Privilege Vulnerability 0.4%
CVE-2023-28224 HIGH 7.1 microsoft windows_10_1507 Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability 0.4%
CVE-2023-23414 HIGH 7.1 microsoft windows_10_1507 Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability 0.4%
CVE-2023-23407 HIGH 7.1 microsoft windows_10_1507 Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability 0.4%
CVE-2026-68806 HIGH 7.8 microsoft 365_apps Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-62816 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network. 0.4%
CVE-2026-54981 HIGH 7.8 microsoft python Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally. 0.4%
CVE-2026-56189 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-62466 HIGH 7.8 microsoft windows_10_1607 Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-62457 HIGH 7.8 microsoft windows_10_1809 Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-47999 MED 6.8 microsoft windows_10_1607 Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. 0.4%
CVE-2024-43580 MED 5.4 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.4%
CVE-2023-24910 HIGH 7.8 microsoft 365 Windows Graphics Component Elevation of Privilege Vulnerability 0.4%
CVE-2023-23419 HIGH 7.8 microsoft windows_11_22h2 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability 0.4%
CVE-2023-23418 HIGH 7.8 microsoft windows_11_22h2 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability 0.4%
CVE-2023-23417 HIGH 7.8 microsoft windows_10_1607 Windows Partition Management Driver Elevation of Privilege Vulnerability 0.4%
CVE-2023-21704 HIGH 7.8 microsoft sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 0.4%
CVE-2023-21528 HIGH 7.8 microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability 0.4%