56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-21280 | MED 5.5 | microsoft windows_10_1507 Windows Virtual Trusted Platform Module Denial of Service Vulnerability | 0.7% | — |
| CVE-2024-43524 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-43523 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-30092 | HIGH 8.0 | microsoft windows_10_1507 Windows Hyper-V Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-21914 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-21885 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-21884 | HIGH 7.8 | microsoft windows_server Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-21835 | HIGH 7.8 | microsoft windows_10 Microsoft Cryptographic Services Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2026-62817 | HIGH 8.8 | microsoft windows_10_1809 Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network. | 0.7% | — |
| CVE-2025-62553 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2023-32016 | MED 5.5 | microsoft windows_10_1507 Windows Installer Information Disclosure Vulnerability | 0.7% | — |
| CVE-2023-29341 | HIGH 7.8 | microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-29340 | HIGH 7.8 | microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-24905 | HIGH 7.8 | microsoft windows_10_20h2 Remote Desktop Client Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-26938 | HIGH 7.0 | microsoft windows_server Storage Spaces Direct Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-42274 | MED 6.8 | microsoft windows_10 Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability | 0.7% | — |
| CVE-2021-26860 | HIGH 7.8 | microsoft windows_10 Windows App-V Overlay Filter Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-62458 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2025-26683 | HIGH 8.1 | microsoft azure_playwright Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2022-23293 | HIGH 7.8 | microsoft windows_10 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2026-66324 | MED 6.5 | microsoft edge_chromium External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2024-43625 | HIGH 8.1 | microsoft windows_11_22h2 Microsoft Windows VMSwitch Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-29132 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-23296 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2026-56162 | CRIT 10.0 | microsoft azure_sql_database Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |