IT
56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.477 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-29822 HIGH 7.8 microsoft office Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally. 0.8%
CVE-2024-21311 MED 5.5 microsoft windows_10_1507 Windows Cryptographic Services Information Disclosure Vulnerability 0.8%
CVE-2023-36559 MED 4.2 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.8%
CVE-2022-24493 MED 5.5 microsoft windows_10 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability 0.8%
CVE-2026-34350 MED 6.5 microsoft windows_server_2025 Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network. 0.8%
CVE-2025-53799 MED 5.5 microsoft 365_copilot Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally. 0.8%
CVE-2026-23658 HIGH 8.6 microsoft azure_devops Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. 0.8%
CVE-2025-49740 HIGH 8.8 microsoft windows_10_1507 Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network. 0.8%
CVE-2025-30398 HIGH 8.1 microsoft nuance_powerscribe_360 Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network. 0.8%
CVE-2024-38170 HIGH 7.1 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0.8%
CVE-2024-30068 HIGH 8.8 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.8%
CVE-2025-27729 HIGH 7.8 microsoft windows_10_21h2 Use after free in Windows Shell allows an unauthorized attacker to execute code locally. 0.8%
CVE-2020-0912 HIGH 7.0 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run 0.8%
CVE-2026-62902 MED 6.5 microsoft .net Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. 0.8%
CVE-2026-50444 HIGH 8.8 microsoft windows_10_1607 Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-50360 HIGH 8.8 microsoft windows_10_21h2 Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-57100 CRIT 9.9 microsoft entra_provisioning_service Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-54998 HIGH 8.8 microsoft exchange_online Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-45499 CRIT 9.9 microsoft azure_openai Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-47647 CRIT 9.9 microsoft dynamics_365 Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-32157 HIGH 8.8 microsoft remote_desktop_client Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-65041 CRIT 10.0 microsoft partner_center Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network. 0.8%
CVE-2025-21296 HIGH 7.5 microsoft windows_10_1507 BranchCache Remote Code Execution Vulnerability 0.8%
CVE-2023-21817 HIGH 7.8 microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability 0.8%
CVE-2020-0806 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0772. 0.8%