IT
56.705 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-59138 MED 6.5 microsoft windows_10_1607 Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network. 1.0%
CVE-2018-8170 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory, aka "Windows Image Elevation of Privilege Vulnerability." This affects Windows 10, Windows 10 Servers. 1.0%
CVE-2021-42307 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability 1.0%
CVE-2026-21250 HIGH 7.8 microsoft windows_11_24h2 Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 1.0%
CVE-2022-37963 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 1.0%
CVE-2021-28322 HIGH 7.8 microsoft visual_studio Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability 1.0%
CVE-2021-28313 HIGH 7.8 microsoft visual_studio Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability 1.0%
CVE-2019-1142 MED 5.5 microsoft .net_framework An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka '.NET Framework Elevation of Privilege Vulnerability'. 1.0%
CVE-2025-62214 MED 6.7 microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally. 1.0%
CVE-2023-38140 MED 5.5 microsoft windows_10_1607 Windows Kernel Information Disclosure Vulnerability 1.0%
CVE-2023-36895 HIGH 7.8 microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability 1.0%
CVE-2026-58529 HIGH 7.1 microsoft windows_11_26h1 Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network. 1.0%
CVE-2026-57991 HIGH 7.4 microsoft edge_chromium Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. 1.0%
CVE-2025-64672 HIGH 8.8 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 1.0%
CVE-2025-64666 HIGH 7.5 microsoft exchange_server Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. 1.0%
CVE-2025-29791 HIGH 7.8 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 1.0%
CVE-2025-27752 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 1.0%
CVE-2024-26181 MED 5.5 microsoft windows_10_1507 Windows Kernel Denial of Service Vulnerability 1.0%
CVE-2020-17097 LOW 3.3 microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability 1.0%
CVE-2020-1011 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows System Assessment Tool improperly handles file operations, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0934, CVE-2020-0983, CVE-2020-1009, CVE-2020-1015 1.0%
CVE-2020-1009 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Microsoft Store Install Service handles file operations in protected locations, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0934, CVE-2020-0983, CVE- 1.0%
CVE-2026-48567 CRIT 10.0 microsoft azure_horizondb Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. 1.0%
CVE-2024-49088 HIGH 7.8 microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 1.0%
CVE-2024-26248 HIGH 7.5 microsoft windows_10_1507 Windows Kerberos Elevation of Privilege Vulnerability 1.0%
CVE-2023-36730 HIGH 7.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 1.0%