56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-48582 | CRIT 9.6 | microsoft exchange_online Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2025-47176 | HIGH 7.8 | microsoft 365_apps '.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally. | 0.7% | — |
| CVE-2024-21432 | HIGH 7.0 | microsoft windows_10_1507 Windows Update Stack Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-16981 | MED 6.1 | microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-53787 | HIGH 8.2 | microsoft 365_copilot_chat Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | 0.7% | — |
| CVE-2025-26643 | MED 5.4 | microsoft edge_chromium The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2023-35355 | HIGH 7.8 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-35374 | HIGH 7.8 | microsoft paint_3d Paint 3D Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-24944 | MED 6.5 | microsoft windows_10_1809 Windows Bluetooth Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2022-41085 | HIGH 7.5 | microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2026-45481 | HIGH 7.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2024-38043 | HIGH 7.8 | microsoft windows_10_1607 PowerShell Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2026-20837 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-29974 | MED 5.7 | microsoft windows_10_1507 Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network. | 0.7% | — |
| CVE-2024-43612 | MED 6.9 | microsoft power_bi_report_server Power BI Report Server Spoofing Vulnerability | 0.7% | — |
| CVE-2023-36046 | HIGH 7.1 | microsoft windows_11_21h2 Windows Authentication Denial of Service Vulnerability | 0.7% | — |
| CVE-2022-29125 | HIGH 7.0 | microsoft windows_10 Windows Push Notifications Apps Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-42288 | MED 5.7 | microsoft windows_10 Windows Hello Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2025-59250 | HIGH 8.1 | microsoft jdbc_driver_for_sql_server Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2025-49715 | HIGH 7.5 | microsoft dynamics_365 Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2025-24083 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-24081 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-24080 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-24079 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2023-28313 | MED 6.1 | microsoft send_customer_voice_survey_from_dynamics_365 Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability | 0.7% | — |