56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-58729 | MED 6.5 | microsoft windows_10_1507 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. | 1.0% | — |
| CVE-2025-33066 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2023-36896 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-35372 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-35371 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-37991 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2022-37988 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2025-32710 | HIGH 8.1 | microsoft windows_server_2008 Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-65037 | CRIT 10.0 | microsoft azure_container_apps Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2024-38010 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2024-37989 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2024-37988 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2024-37986 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2024-37974 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2024-37972 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2020-17074 | HIGH 7.8 | microsoft windows_10 Windows Update Orchestrator Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-16995 | HIGH 7.8 | microsoft network_watcher_agent <p>An elevation of privilege vulnerability exists in Network Watcher Agent virtual machine extension for Linux. An attacker who successfully exploited this vulnerability could execute code with elevated privileges.</p> <p>To exploit this vulnerability, an atta | 1.0% | — |
| CVE-2023-36420 | HIGH 7.8 | microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36417 | HIGH 7.8 | microsoft ole_db_driver_for_sql_server Microsoft SQL OLE DB Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2025-64670 | MED 6.5 | microsoft windows_10_21h2 Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2024-49038 | CRIT 9.3 | microsoft copilot_studio Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network. | 1.0% | — |
| CVE-2021-28326 | MED 5.5 | microsoft windows_10 Windows AppX Deployment Server Denial of Service Vulnerability | 1.0% | — |
| CVE-2019-1323 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges, aka 'Microsoft Windows Update Client Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1336. | 1.0% | — |
| CVE-2023-36045 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-28300 | HIGH 7.5 | microsoft azure_service_connector Azure Service Connector Security Feature Bypass Vulnerability | 1.0% | — |