56.761 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.477 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-64675 | HIGH 8.3 | microsoft azure_cosmos_db Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2023-21737 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-21736 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-21735 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-26928 | HIGH 7.0 | microsoft windows_10 Windows Photo Import API Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-49744 | HIGH 7.0 | microsoft windows_10_1507 Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2024-26172 | MED 5.5 | microsoft windows_10_1809 Windows DWM Core Library Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-21387 | MED 5.3 | microsoft edge_chromium Microsoft Edge for Android Spoofing Vulnerability | 0.7% | — |
| CVE-2023-32028 | HIGH 7.8 | microsoft ole_db_driver_for_sql_server Microsoft SQL OLE DB Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-32026 | HIGH 7.8 | microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2026-56165 | CRIT 9.8 | microsoft account Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-64663 | CRIT 9.9 | microsoft azure_language Custom Question Answering Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-21356 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-28922 | MED 4.1 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-21436 | HIGH 7.8 | microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-24465 | LOW 3.3 | microsoft intune_company_portal Microsoft Intune Portal for iOS Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2021-33765 | MED 6.2 | microsoft windows_10 Windows Installer Spoofing Vulnerability | 0.7% | — |
| CVE-2020-1159 | MED 6.6 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in the way that the StartTileData.dll handles file creation in protected locations. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>To exploit the v | 0.7% | — |
| CVE-2026-57985 | HIGH 7.6 | microsoft edge_chromium Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-33105 | CRIT 10.0 | microsoft azure_kubernetes_service Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2025-21213 | MED 4.6 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-20721 | MED 5.5 | adobe acrobat Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current | 0.7% | — |
| CVE-2023-35331 | MED 6.5 | microsoft windows_server_2012 Windows Local Security Authority (LSA) Denial of Service Vulnerability | 0.7% | — |
| CVE-2023-21774 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-21772 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |