56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-24095 | HIGH 7.0 | microsoft windows_10 DirectX Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2026-23659 | HIGH 8.6 | microsoft azure_data_factory Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2023-36026 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.8% | — |
| CVE-2023-35335 | HIGH 8.2 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.8% | — |
| CVE-2022-26920 | MED 5.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-41376 | LOW 2.3 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 0.8% | — |
| CVE-2019-1488 | LOW 3.3 | microsoft windows_10 A security feature bypass vulnerability exists when Microsoft Defender improperly handles specific buffers, aka 'Microsoft Defender Security Feature Bypass Vulnerability'. | 0.8% | — |
| CVE-2026-20951 | HIGH 7.8 | microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | 0.8% | — |
| CVE-2025-60723 | MED 6.3 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny service over a network. | 0.8% | — |
| CVE-2024-49111 | MED 6.6 | microsoft windows_10_1809 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-36872 | MED 5.5 | microsoft vp9_video_extensions VP9 Video Extensions Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-22712 | MED 5.6 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-21363 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-41063 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2021-31961 | MED 6.1 | microsoft windows_10 Windows InstallService Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-43465 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-26806 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2026-26164 | HIGH 7.5 | microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2025-49739 | HIGH 8.8 | microsoft visual_studio Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2023-21567 | MED 5.6 | microsoft visual_studio_2017 Visual Studio Denial of Service Vulnerability | 0.8% | — |
| CVE-2021-1703 | HIGH 7.8 | microsoft windows_10 Windows Event Logging Service Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1650 | HIGH 7.8 | microsoft windows_10 Windows Runtime C++ Template Library Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2025-62562 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally. | 0.8% | — |
| CVE-2022-41079 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 0.8% | — |
| CVE-2022-41078 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 0.8% | — |