IT
56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-38209 HIGH 7.8 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 0.7%
CVE-2026-62913 HIGH 8.8 microsoft exchange_server Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. 0.7%
CVE-2026-41107 HIGH 7.4 microsoft edge_chromium External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2026-20943 HIGH 7.0 microsoft office Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally. 0.7%
CVE-2024-43547 MED 6.5 microsoft windows_10_1507 Windows Kerberos Information Disclosure Vulnerability 0.7%
CVE-2024-28916 HIGH 8.8 microsoft xbox_gaming_services Xbox Gaming Services Elevation of Privilege Vulnerability 0.7%
CVE-2026-69550 MED 6.5 microsoft windows_app Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2026-65794 MED 6.5 microsoft windows_10_1607 Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2026-26136 MED 6.5 microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2025-53763 CRIT 9.8 microsoft purview_data_governance Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. 0.7%
CVE-2024-38163 HIGH 7.8 microsoft windows_10_21h2 Windows Update Stack Elevation of Privilege Vulnerability 0.7%
CVE-2021-40470 HIGH 7.8 microsoft windows_10 DirectX Graphics Kernel Elevation of Privilege Vulnerability 0.7%
CVE-2021-40466 HIGH 7.8 microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability 0.7%
CVE-2021-40443 HIGH 7.8 microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability 0.7%
CVE-2026-65813 MED 6.5 microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2025-53804 MED 5.5 microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. 0.7%
CVE-2025-53803 MED 5.5 microsoft windows_10_1507 Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. 0.7%
CVE-2025-30386 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.7%
CVE-2025-21402 HIGH 7.8 microsoft office Microsoft Office OneNote Remote Code Execution Vulnerability 0.7%
CVE-2024-43503 HIGH 7.8 microsoft sharepoint_server Microsoft SharePoint Elevation of Privilege Vulnerability 0.7%
CVE-2024-26245 HIGH 7.8 microsoft windows_10_1507 Windows SMB Elevation of Privilege Vulnerability 0.7%
CVE-2023-35323 HIGH 7.8 microsoft windows_11_21h2 Windows OLE Remote Code Execution Vulnerability 0.7%
CVE-2023-35313 HIGH 7.8 microsoft windows_10_1507 Windows Online Certificate Status Protocol (OCSP) SnapIn Remote Code Execution Vulnerability 0.7%
CVE-2023-23377 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0.7%
CVE-2026-55126 HIGH 7.3 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.6%