IT
57.056 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-49705 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-49700 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.4%
CVE-2024-43511 HIGH 7.0 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.4%
CVE-2023-21725 MED 6.3 microsoft windows_malicious_software_removal_tool Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability 0.4%
CVE-2026-63525 HIGH 7.8 microsoft 365_apps Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-58613 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-21264 CRIT 9.3 microsoft account Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2025-59260 MED 5.5 microsoft windows_server_2016 Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally. 0.4%
CVE-2025-29841 HIGH 7.0 microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-70325 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-70323 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-70322 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-70320 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-70319 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-70316 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-70315 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-50475 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-45500 MED 6.1 microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2025-59511 HIGH 7.8 microsoft windows_10_1809 External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-54112 HIGH 7.0 microsoft windows_10_1507 Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-54111 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-54099 HIGH 7.0 microsoft windows_10_1507 Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-53802 HIGH 7.0 microsoft windows_10_21h2 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-49659 HIGH 7.8 microsoft windows_10_1507 Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-55012 HIGH 7.8 microsoft malware_protection_engine Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally. 0.4%