56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-28901 | MED 5.5 | microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-28900 | MED 5.5 | microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.7% | — |
| CVE-2023-23421 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-47158 | CRIT 9.0 | microsoft azure_devops Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2025-21322 | HIGH 7.8 | microsoft pc_manager Microsoft PC Manager Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-38047 | HIGH 7.8 | microsoft windows_10_1607 PowerShell Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-33171 | HIGH 8.2 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.7% | — |
| CVE-2023-28314 | MED 6.1 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.7% | — |
| CVE-2023-21753 | MED 5.5 | microsoft windows_10 Event Tracing for Windows Information Disclosure Vulnerability | 0.7% | — |
| CVE-2022-21867 | HIGH 7.0 | microsoft windows_10 Windows Push Notifications Apps Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-21863 | HIGH 7.0 | microsoft windows_10 Windows StateRepository API Server file Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-16983 | MED 5.7 | microsoft azure_sphere Azure Sphere Tampering Vulnerability | 0.7% | — |
| CVE-2025-62220 | HIGH 8.8 | microsoft windows_subsystem_for_linux Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-21346 | HIGH 7.1 | microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2026-40376 | HIGH 7.5 | microsoft visual_studio_code Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2025-55248 | MED 4.8 | microsoft .net Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2024-20686 | HIGH 7.8 | microsoft windows_server_2022_23h2 Win32k Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-35343 | HIGH 7.8 | microsoft windows_10_1809 Windows Geolocation Service Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-28226 | MED 5.3 | microsoft windows_10_1507 Windows Enroll Engine Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2022-21973 | MED 5.5 | microsoft windows_7 Windows Media Center Update Denial of Service Vulnerability | 0.7% | — |
| CVE-2026-70329 | HIGH 8.8 | microsoft 365_apps Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-47298 | HIGH 8.0 | microsoft sharepoint_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-24988 | MED 6.6 | microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack. | 0.7% | — |
| CVE-2025-24987 | MED 6.6 | microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack. | 0.7% | — |
| CVE-2025-21284 | MED 5.5 | microsoft windows_10_1507 Windows Virtual Trusted Platform Module Denial of Service Vulnerability | 0.7% | — |