IT
56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-36558 MED 6.2 microsoft .net ASP.NET Core Security Feature Bypass Vulnerability 1.1%
CVE-2022-34302 MED 6.7 horizondatasys uefi_bootloader A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace 1.1%
CVE-2018-8455 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windo 1.1%
CVE-2018-8232 HIGH 7.8 microsoft visual_studio_2017 A Tampering vulnerability exists when Microsoft Macro Assembler improperly validates code, aka "Microsoft Macro Assembler Tampering Vulnerability." This affects Microsoft Visual Studio. 1.1%
CVE-2026-54130 CRIT 9.8 microsoft 365_copilot Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. 1.1%
CVE-2023-21548 HIGH 8.1 microsoft windows_10_1607 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 1.1%
CVE-2023-21535 HIGH 8.1 microsoft windows_10_1607 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 1.1%
CVE-2021-26889 HIGH 7.8 microsoft windows_10 Windows Update Stack Elevation of Privilege Vulnerability 1.1%
CVE-2019-0892 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. 1.1%
CVE-2019-0766 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege 1.1%
CVE-2019-0696 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. 1.1%
CVE-2018-8441 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists due to an integer overflow in Windows Subsystem for Linux, aka "Windows Subsystem for Linux Elevation of Privilege Vulnerability." This affects Windows 10, Windows 10 Servers. 1.1%
CVE-2017-8466 HIGH 7.8 microsoft windows_10 Windows Cursor in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows improper elevation of privilege, aka "Windows Cursor Elevation of Privilege Vulnerability". 1.1%
CVE-2024-49071 MED 6.5 microsoft defender_for_endpoint Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network. 1.1%
CVE-2025-62456 HIGH 8.8 microsoft windows_11_23h2 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network. 1.1%
CVE-2025-26687 HIGH 7.5 microsoft 365_copilot Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. 1.1%
CVE-2025-21393 MED 6.3 microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability 1.1%
CVE-2021-43221 MED 4.2 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.1%
CVE-2021-34483 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 1.1%
CVE-2026-54108 MED 6.5 microsoft sharepoint_server External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 1.1%
CVE-2025-53767 CRIT 10.0 microsoft azure_openai Azure OpenAI Elevation of Privilege Vulnerability 1.1%
CVE-2024-49120 HIGH 8.1 microsoft windows_server_2012 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.1%
CVE-2022-23266 HIGH 7.8 microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability 1.1%
CVE-2020-1250 MED 5.5 microsoft windows_10 <p>An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit thi 1.1%
CVE-2020-1119 MED 5.5 microsoft windows_10 <p>An information disclosure vulnerability exists when StartTileData.dll improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit this vul 1.1%