IT
56.747 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.477 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-41165 HIGH 7.1 microsoft word A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this 0.7%
CVE-2020-1371 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Event Logging Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Event Logging Service Elevation of 0.7%
CVE-2020-1363 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Picker Platform Elevation of Privilege Vu 0.7%
CVE-2020-1352 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows USO Core Worker improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows USO Core Worker Elevation of Privilege Vu 0.7%
CVE-2026-62835 CRIT 9.3 microsoft azure_portal Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2024-28921 MED 6.7 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.7%
CVE-2025-24053 HIGH 7.2 microsoft dataverse Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2024-28903 MED 6.7 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.7%
CVE-2026-47644 MED 6.5 microsoft copilot_chat Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2025-29820 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.7%
CVE-2025-21179 MED 4.8 microsoft windows_11_24h2 DHCP Client Service Denial of Service Vulnerability 0.7%
CVE-2025-21257 MED 5.5 microsoft windows_10_1607 Windows WLAN AutoConfig Service Information Disclosure Vulnerability 0.7%
CVE-2024-43626 HIGH 7.8 microsoft windows_10_1507 Windows Telephony Service Elevation of Privilege Vulnerability 0.7%
CVE-2024-30041 MED 5.4 microsoft bing_search Microsoft Bing Search Spoofing Vulnerability 0.7%
CVE-2021-41343 MED 5.5 microsoft windows_10 Windows Fast FAT File System Driver Information Disclosure Vulnerability 0.7%
CVE-2021-41336 MED 5.5 microsoft windows_11 Windows Kernel Information Disclosure Vulnerability 0.7%
CVE-2021-40475 MED 5.5 microsoft windows_10 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability 0.7%
CVE-2021-40472 MED 5.5 microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability 0.7%
CVE-2021-40468 MED 5.5 microsoft windows_10 Windows Bind Filter Driver Information Disclosure Vulnerability 0.7%
CVE-2021-38663 MED 5.5 microsoft windows_10 Windows exFAT File System Information Disclosure Vulnerability 0.7%
CVE-2024-29064 MED 6.2 microsoft windows_10_1507 Windows Hyper-V Denial of Service Vulnerability 0.7%
CVE-2024-26241 HIGH 7.8 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 0.7%
CVE-2022-22713 MED 5.6 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 0.7%
CVE-2022-21905 MED 4.6 microsoft windows_10 Windows Hyper-V Security Feature Bypass Vulnerability 0.7%
CVE-2020-0822 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file operations, aka 'Windows Language Pack Installer Elevation of Privilege Vulnerability'. 0.7%