56.727 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.472 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-50162 | HIGH 8.0 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-50160 | HIGH 8.0 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2022-34303 | MED 6.7 | eurosoft-uk uefi_bootloader A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existin | 0.8% | — |
| CVE-2026-45504 | HIGH 8.8 | microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2022-39343 | MED 5.6 | microsoft azure_rtos_filex Azure RTOS FileX is a FAT-compatible file system that’s fully integrated with Azure RTOS ThreadX. In versions before 6.2.0, the Fault Tolerant feature of Azure RTOS FileX includes integer under and overflows which may be exploited to achieve buffer overflow an | 0.8% | — |
| CVE-2022-38049 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2021-26878 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-0773 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows ActiveX Installer Service Eleva | 0.8% | — |
| CVE-2020-0771 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows CSC Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows CSC Service Elevation of Privilege Vulnerabil | 0.8% | — |
| CVE-2020-0770 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows ActiveX Installer Service Eleva | 0.8% | — |
| CVE-2026-21257 | HIGH 8.0 | microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-27743 | HIGH 7.8 | microsoft system_center_data_protection_manager Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. | 0.8% | — |
| CVE-2026-41094 | HIGH 8.8 | microsoft data_formulator Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-21532 | HIGH 8.2 | microsoft azure_functions Azure Function Information Disclosure Vulnerability | 0.8% | — |
| CVE-2025-30389 | HIGH 8.7 | microsoft azure_ai_bot_service Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-21344 | HIGH 7.8 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-21978 | HIGH 8.2 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-30065 | MED 5.5 | microsoft windows_10_1507 Windows Themes Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-20693 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-33146 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2017-8561 | HIGH 7.0 | microsoft windows_10 Windows kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it handles objects in memory, aka "Windows Ke | 0.8% | — |
| CVE-2026-50651 | HIGH 7.5 | microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | 0.8% | — |
| CVE-2026-50648 | HIGH 7.5 | microsoft .net Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. | 0.8% | — |
| CVE-2026-50527 | HIGH 7.5 | microsoft .net Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. | 0.8% | — |
| CVE-2026-56185 | MED 6.5 | microsoft windows_admin_center Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network. | 0.8% | — |