IT
56.736 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.474 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-21390 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0.8%
CVE-2025-21386 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0.8%
CVE-2024-38169 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0.8%
CVE-2021-41345 HIGH 7.8 microsoft windows_10 Storage Spaces Controller Elevation of Privilege Vulnerability 0.8%
CVE-2019-1478 HIGH 7.8 microsoft windows_7 An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'. 0.8%
CVE-2019-1438 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1407, CVE-2019-1433, CVE-2019-14 0.8%
CVE-2019-1434 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1394, CVE-2019-1395, 0.8%
CVE-2019-1392 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. 0.8%
CVE-2025-29826 HIGH 7.3 microsoft dataverse Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2025-29817 MED 5.7 microsoft power_automate_for_desktop Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network. 0.8%
CVE-2025-29812 HIGH 7.8 microsoft windows_11_22h2 Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. 0.8%
CVE-2024-49092 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability 0.8%
CVE-2024-49083 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability 0.8%
CVE-2024-26176 HIGH 7.8 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.8%
CVE-2023-21748 HIGH 7.8 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0.8%
CVE-2023-21675 HIGH 7.8 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0.8%
CVE-2022-41052 HIGH 7.8 microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability 0.8%
CVE-2025-27750 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.8%
CVE-2025-27746 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.8%
CVE-2025-21292 HIGH 8.8 microsoft windows_10_1809 Windows Search Service Elevation of Privilege Vulnerability 0.8%
CVE-2024-21442 HIGH 7.8 microsoft windows_10_21h2 Windows USB Print Driver Elevation of Privilege Vulnerability 0.8%
CVE-2024-21434 HIGH 7.8 microsoft windows_10_1507 Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability 0.8%
CVE-2025-55333 MED 6.1 microsoft windows_10_1507 Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.8%
CVE-2023-33139 MED 5.5 microsoft visual_studio Visual Studio Information Disclosure Vulnerability 0.8%
CVE-2022-47211 HIGH 7.8 microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability 0.8%