IT
56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.471 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-50447 CRIT 9.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2026-49172 CRIT 9.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2026-42990 CRIT 9.8 microsoft windows_10_1607 Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2021-33760 MED 5.5 microsoft windows_10 Media Foundation Information Disclosure Vulnerability 1.0%
CVE-2025-50171 CRIT 9.1 microsoft windows_server_2022 Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network. 1.0%
CVE-2023-28283 HIGH 8.1 microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 1.0%
CVE-2021-27094 MED 4.4 microsoft windows_10 Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability 1.0%
CVE-2020-0621 MED 4.4 microsoft windows_10 A security feature bypass vulnerability exists in Windows 10 when third party filters are called during a password update, aka 'Windows Security Feature Bypass Vulnerability'. 1.0%
CVE-2017-8590 HIGH 8.8 microsoft windows_10 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way that the Windows C 1.0%
CVE-2025-49717 HIGH 8.5 microsoft sql_server_2019 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. 1.0%
CVE-2024-21374 MED 5.0 microsoft teams Microsoft Teams for Android Information Disclosure Vulnerability 1.0%
CVE-2022-38020 HIGH 7.3 microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability 1.0%
CVE-2022-30197 MED 5.5 microsoft windows_10 Windows Kernel Information Disclosure Vulnerability 1.0%
CVE-2026-50646 HIGH 7.8 microsoft .net Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. 1.0%
CVE-2025-48817 HIGH 8.8 microsoft remote_desktop_client Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2025-29831 HIGH 7.5 microsoft windows_server_2008 Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2023-35394 MED 4.6 microsoft azure_hdinsight Azure HDInsight Jupyter Notebook Spoofing Vulnerability 1.0%
CVE-2022-38037 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 1.0%
CVE-2022-21964 MED 5.5 microsoft windows_10 Remote Desktop Licensing Diagnoser Information Disclosure Vulnerability 1.0%
CVE-2025-24070 HIGH 7.0 microsoft asp.net_core Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network. 1.0%
CVE-2023-21778 HIGH 8.0 microsoft dynamics_365 Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability 1.0%
CVE-2025-29819 MED 6.2 microsoft windows_admin_center External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally. 1.0%
CVE-2023-36592 HIGH 7.3 microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%
CVE-2023-36589 HIGH 7.3 microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%
CVE-2023-36575 HIGH 7.3 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%