IT
56.761 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.477 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-64675 HIGH 8.3 microsoft azure_cosmos_db Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network. 0.7%
CVE-2023-21737 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0.7%
CVE-2023-21736 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0.7%
CVE-2023-21735 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 0.7%
CVE-2022-26928 HIGH 7.0 microsoft windows_10 Windows Photo Import API Elevation of Privilege Vulnerability 0.7%
CVE-2025-49744 HIGH 7.0 microsoft windows_10_1507 Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0.7%
CVE-2024-26172 MED 5.5 microsoft windows_10_1809 Windows DWM Core Library Information Disclosure Vulnerability 0.7%
CVE-2024-21387 MED 5.3 microsoft edge_chromium Microsoft Edge for Android Spoofing Vulnerability 0.7%
CVE-2023-32028 HIGH 7.8 microsoft ole_db_driver_for_sql_server Microsoft SQL OLE DB Remote Code Execution Vulnerability 0.7%
CVE-2023-32026 HIGH 7.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 0.7%
CVE-2026-56165 CRIT 9.8 microsoft account Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2025-64663 CRIT 9.9 microsoft azure_language Custom Question Answering Elevation of Privilege Vulnerability 0.7%
CVE-2025-21356 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0.7%
CVE-2024-28922 MED 4.1 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.7%
CVE-2024-21436 HIGH 7.8 microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability 0.7%
CVE-2022-24465 LOW 3.3 microsoft intune_company_portal Microsoft Intune Portal for iOS Security Feature Bypass Vulnerability 0.7%
CVE-2021-33765 MED 6.2 microsoft windows_10 Windows Installer Spoofing Vulnerability 0.7%
CVE-2020-1159 MED 6.6 microsoft windows_10 <p>An elevation of privilege vulnerability exists in the way that the StartTileData.dll handles file creation in protected locations. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>To exploit the v 0.7%
CVE-2026-57985 HIGH 7.6 microsoft edge_chromium Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2026-33105 CRIT 10.0 microsoft azure_kubernetes_service Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2025-21213 MED 4.6 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.7%
CVE-2024-20721 MED 5.5 adobe acrobat Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current 0.7%
CVE-2023-35331 MED 6.5 microsoft windows_server_2012 Windows Local Security Authority (LSA) Denial of Service Vulnerability 0.7%
CVE-2023-21774 HIGH 7.8 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0.7%
CVE-2023-21772 HIGH 7.8 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0.7%