IT
56.743 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.477 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-49044 MED 6.7 microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability 0.8%
CVE-2024-38166 HIGH 8.2 microsoft dynamics_crm_service_portal_web_resource An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link. 0.8%
CVE-2023-38161 HIGH 7.8 microsoft windows_10_1507 Windows GDI Elevation of Privilege Vulnerability 0.8%
CVE-2023-32051 HIGH 7.8 microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability 0.8%
CVE-2021-43246 MED 5.6 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 0.8%
CVE-2026-70306 CRIT 9.3 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 0.7%
CVE-2025-62222 HIGH 8.8 microsoft github_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2025-21416 HIGH 8.5 microsoft azure_virtual_desktop Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2023-23420 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0.7%
CVE-2021-34514 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0.7%
CVE-2020-0632 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- 0.7%
CVE-2020-0630 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- 0.7%
CVE-2020-0629 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- 0.7%
CVE-2020-0626 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- 0.7%
CVE-2020-0620 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Microsoft Cryptographic Services improperly handles files, aka 'Microsoft Cryptographic Services Elevation of Privilege Vulnerability'. 0.7%
CVE-2026-42833 CRIT 9.1 microsoft dynamics_365 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. 0.7%
CVE-2025-49674 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2024-37984 HIGH 8.4 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.7%
CVE-2024-29989 HIGH 8.4 microsoft azure_monitor_agent Azure Monitor Agent Elevation of Privilege Vulnerability 0.7%
CVE-2023-28309 HIGH 7.6 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.7%
CVE-2026-35423 MED 5.4 microsoft windows_10_1607 Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2026-32151 MED 6.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. 0.7%
CVE-2025-21361 HIGH 7.8 microsoft office Microsoft Outlook Remote Code Execution Vulnerability 0.7%
CVE-2025-21187 HIGH 7.8 microsoft power_automate_for_desktop Microsoft Power Automate Remote Code Execution Vulnerability 0.7%
CVE-2024-43505 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0.7%