IT
56.736 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.474 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-1232 HIGH 7.8 microsoft visual_studio An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations, aka 'Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability'. 0.8%
CVE-2025-25007 MED 5.3 microsoft exchange_server Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 0.8%
CVE-2023-21747 HIGH 7.8 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0.8%
CVE-2022-41107 HIGH 7.8 microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability 0.8%
CVE-2020-1245 HIGH 7.0 microsoft windows_10 <p>An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install 0.8%
CVE-2021-43211 MED 5.5 microsoft windows_10_update_assistant Windows 10 Update Assistant Elevation of Privilege Vulnerability 0.8%
CVE-2026-49179 HIGH 8.8 microsoft windows_10_1607 Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-41098 HIGH 8.4 microsoft azure_stack_edge Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network. 0.8%
CVE-2022-30223 MED 5.7 microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability 0.8%
CVE-2026-26151 HIGH 7.1 microsoft windows_10_1607 Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network. 0.8%
CVE-2025-21194 HIGH 7.1 microsoft surface_go_2_1901_firmware Microsoft Surface Security Feature Bypass Vulnerability 0.8%
CVE-2024-43529 HIGH 7.3 microsoft windows_10_21h2 Windows Print Spooler Elevation of Privilege Vulnerability 0.8%
CVE-2024-35255 MED 5.5 microsoft authentication_library Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability 0.8%
CVE-2022-35773 HIGH 7.8 microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability 0.8%
CVE-2022-34687 HIGH 7.8 microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability 0.8%
CVE-2019-1176 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delet 0.8%
CVE-2026-61924 MED 6.5 microsoft windows_10_1607 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. 0.8%
CVE-2026-61921 MED 6.5 microsoft windows_10_1607 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. 0.8%
CVE-2023-37142 MED 5.5 microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees(). 0.8%
CVE-2023-37141 MED 5.5 microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers::ProfiledNewScArray(). 0.8%
CVE-2023-37140 MED 5.5 microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::DiagScopeVariablesWalker::GetChildrenCount(). 0.8%
CVE-2026-41105 HIGH 8.1 microsoft azure_monitor_action_group_notification_system Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-32211 CRIT 9.1 microsoft azure_web_apps Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network. 0.8%
CVE-2025-21394 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0.8%
CVE-2025-21392 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 0.8%