56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-35310 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2025-49695 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2024-49053 | HIGH 7.6 | microsoft dynamics_365_sales Microsoft Dynamics 365 Sales Spoofing Vulnerability | 0.7% | — |
| CVE-2024-37985 | MED 5.9 | microsoft windows_11_22h2 Windows Kernel Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-38084 | HIGH 7.8 | microsoft officeplus Microsoft OfficePlus Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-32020 | MED 5.6 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 0.7% | — |
| CVE-2023-23390 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-23378 | HIGH 7.8 | microsoft print_3d Print 3D Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2026-50485 | MED 4.5 | microsoft windows_10_1607 Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network. | 0.7% | — |
| CVE-2025-49689 | HIGH 7.8 | microsoft windows_10_1507 Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2025-29823 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2024-37304 | MED 6.1 | microsoft nugetgallery NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately | 0.7% | — |
| CVE-2022-21928 | MED 6.3 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-21868 | HIGH 7.0 | microsoft windows_10 Windows Devices Human Interface Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-43880 | MED 5.5 | microsoft windows_11 Windows Mobile Device Management Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2026-25180 | MED 5.5 | microsoft 365_copilot Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. | 0.7% | — |
| CVE-2024-43501 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-29061 | HIGH 7.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2023-32037 | MED 6.5 | microsoft windows_10_1809 Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2022-24544 | HIGH 7.8 | microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2026-50502 | HIGH 8.0 | microsoft windows_10_1607 Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2023-21807 | MED 6.5 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.7% | — |
| CVE-2022-35795 | HIGH 7.8 | microsoft windows_10 Windows Error Reporting Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-30132 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-38210 | HIGH 7.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.7% | — |