56.706 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.471 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-50447 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-49172 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-42990 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2021-33760 | MED 5.5 | microsoft windows_10 Media Foundation Information Disclosure Vulnerability | 1.0% | — |
| CVE-2025-50171 | CRIT 9.1 | microsoft windows_server_2022 Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network. | 1.0% | — |
| CVE-2023-28283 | HIGH 8.1 | microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2021-27094 | MED 4.4 | microsoft windows_10 Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2020-0621 | MED 4.4 | microsoft windows_10 A security feature bypass vulnerability exists in Windows 10 when third party filters are called during a password update, aka 'Windows Security Feature Bypass Vulnerability'. | 1.0% | — |
| CVE-2017-8590 | HIGH 8.8 | microsoft windows_10 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way that the Windows C | 1.0% | — |
| CVE-2025-49717 | HIGH 8.5 | microsoft sql_server_2019 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | 1.0% | — |
| CVE-2024-21374 | MED 5.0 | microsoft teams Microsoft Teams for Android Information Disclosure Vulnerability | 1.0% | — |
| CVE-2022-38020 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2022-30197 | MED 5.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 1.0% | — |
| CVE-2026-50646 | HIGH 7.8 | microsoft .net Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. | 1.0% | — |
| CVE-2025-48817 | HIGH 8.8 | microsoft remote_desktop_client Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-29831 | HIGH 7.5 | microsoft windows_server_2008 Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2023-35394 | MED 4.6 | microsoft azure_hdinsight Azure HDInsight Jupyter Notebook Spoofing Vulnerability | 1.0% | — |
| CVE-2022-38037 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2022-21964 | MED 5.5 | microsoft windows_10 Remote Desktop Licensing Diagnoser Information Disclosure Vulnerability | 1.0% | — |
| CVE-2025-24070 | HIGH 7.0 | microsoft asp.net_core Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2023-21778 | HIGH 8.0 | microsoft dynamics_365 Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2025-29819 | MED 6.2 | microsoft windows_admin_center External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally. | 1.0% | — |
| CVE-2023-36592 | HIGH 7.3 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36589 | HIGH 7.3 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36575 | HIGH 7.3 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1.0% | — |