IT
56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-48582 CRIT 9.6 microsoft exchange_online Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2025-47176 HIGH 7.8 microsoft 365_apps '.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally. 0.7%
CVE-2024-21432 HIGH 7.0 microsoft windows_10_1507 Windows Update Stack Elevation of Privilege Vulnerability 0.7%
CVE-2020-16981 MED 6.1 microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability 0.7%
CVE-2025-53787 HIGH 8.2 microsoft 365_copilot_chat Microsoft 365 Copilot BizChat Information Disclosure Vulnerability 0.7%
CVE-2025-26643 MED 5.4 microsoft edge_chromium The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.7%
CVE-2023-35355 HIGH 7.8 microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 0.7%
CVE-2023-35374 HIGH 7.8 microsoft paint_3d Paint 3D Remote Code Execution Vulnerability 0.7%
CVE-2023-24944 MED 6.5 microsoft windows_10_1809 Windows Bluetooth Driver Information Disclosure Vulnerability 0.7%
CVE-2022-41085 HIGH 7.5 microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability 0.7%
CVE-2026-45481 HIGH 7.3 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.7%
CVE-2024-38043 HIGH 7.8 microsoft windows_10_1607 PowerShell Elevation of Privilege Vulnerability 0.7%
CVE-2026-20837 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. 0.7%
CVE-2025-29974 MED 5.7 microsoft windows_10_1507 Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network. 0.7%
CVE-2024-43612 MED 6.9 microsoft power_bi_report_server Power BI Report Server Spoofing Vulnerability 0.7%
CVE-2023-36046 HIGH 7.1 microsoft windows_11_21h2 Windows Authentication Denial of Service Vulnerability 0.7%
CVE-2022-29125 HIGH 7.0 microsoft windows_10 Windows Push Notifications Apps Elevation of Privilege Vulnerability 0.7%
CVE-2021-42288 MED 5.7 microsoft windows_10 Windows Hello Security Feature Bypass Vulnerability 0.7%
CVE-2025-59250 HIGH 8.1 microsoft jdbc_driver_for_sql_server Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network. 0.7%
CVE-2025-49715 HIGH 7.5 microsoft dynamics_365 Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2025-24083 HIGH 7.8 microsoft 365_apps Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. 0.7%
CVE-2025-24081 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.7%
CVE-2025-24080 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.7%
CVE-2025-24079 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.7%
CVE-2023-28313 MED 6.1 microsoft send_customer_voice_survey_from_dynamics_365 Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability 0.7%