56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-29822 | HIGH 7.8 | microsoft office Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally. | 0.8% | — |
| CVE-2024-21311 | MED 5.5 | microsoft windows_10_1507 Windows Cryptographic Services Information Disclosure Vulnerability | 0.8% | — |
| CVE-2023-36559 | MED 4.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.8% | — |
| CVE-2022-24493 | MED 5.5 | microsoft windows_10 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | 0.8% | — |
| CVE-2026-34350 | MED 6.5 | microsoft windows_server_2025 Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network. | 0.8% | — |
| CVE-2025-53799 | MED 5.5 | microsoft 365_copilot Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally. | 0.8% | — |
| CVE-2026-23658 | HIGH 8.6 | microsoft azure_devops Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-49740 | HIGH 8.8 | microsoft windows_10_1507 Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network. | 0.8% | — |
| CVE-2025-30398 | HIGH 8.1 | microsoft nuance_powerscribe_360 Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2024-38170 | HIGH 7.1 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-30068 | HIGH 8.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2025-27729 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Windows Shell allows an unauthorized attacker to execute code locally. | 0.8% | — |
| CVE-2020-0912 | HIGH 7.0 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run | 0.8% | — |
| CVE-2026-62902 | MED 6.5 | microsoft .net Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-50444 | HIGH 8.8 | microsoft windows_10_1607 Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-50360 | HIGH 8.8 | microsoft windows_10_21h2 Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-57100 | CRIT 9.9 | microsoft entra_provisioning_service Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-54998 | HIGH 8.8 | microsoft exchange_online Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-45499 | CRIT 9.9 | microsoft azure_openai Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-47647 | CRIT 9.9 | microsoft dynamics_365 Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-32157 | HIGH 8.8 | microsoft remote_desktop_client Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-65041 | CRIT 10.0 | microsoft partner_center Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-21296 | HIGH 7.5 | microsoft windows_10_1507 BranchCache Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2023-21817 | HIGH 7.8 | microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-0806 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0772. | 0.8% | — |