56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-26634 | HIGH 7.5 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2024-43614 | MED 5.5 | microsoft defender_for_endpoint Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally. | 0.6% | — |
| CVE-2024-38097 | HIGH 7.1 | microsoft azure_monitor_agent Azure Monitor Agent Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-29991 | MED 5.0 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-21377 | MED 5.5 | microsoft windows_10_1507 Windows DNS Information Disclosure Vulnerability | 0.6% | — |
| CVE-2026-57983 | HIGH 8.7 | microsoft edge_chromium Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | 0.6% | — |
| CVE-2025-21347 | MED 6.0 | microsoft windows_10_1507 Windows Deployment Services Denial of Service Vulnerability | 0.6% | — |
| CVE-2023-23391 | MED 5.5 | microsoft 365_copilot Office for Android Spoofing Vulnerability | 0.6% | — |
| CVE-2022-37971 | HIGH 7.1 | microsoft malware_protection_engine Microsoft Windows Defender Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-31185 | MED 5.5 | microsoft windows_10 Windows Desktop Bridge Denial of Service Vulnerability | 0.6% | — |
| CVE-2021-28443 | MED 5.5 | microsoft windows_10 Windows Console Driver Denial of Service Vulnerability | 0.6% | — |
| CVE-2026-24299 | MED 5.3 | microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2024-38201 | HIGH 7.0 | microsoft azure_stack_hub Azure Stack Hub Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-38029 | HIGH 7.0 | microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-31171 | MED 4.1 | microsoft sharepoint_foundation Microsoft SharePoint Information Disclosure Vulnerability | 0.6% | — |
| CVE-2021-1682 | HIGH 7.0 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-43513 | MED 6.4 | microsoft windows_10_1507 BitLocker Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-37973 | HIGH 8.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-26246 | LOW 3.9 | microsoft edge Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2021-33784 | HIGH 7.8 | microsoft windows_10 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-33759 | HIGH 7.8 | microsoft windows_10 Windows Desktop Bridge Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-33743 | HIGH 7.8 | microsoft windows_10 Windows Projected File System Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-54901 | MED 5.5 | microsoft 365_apps Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2022-38015 | MED 6.5 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0.6% | — |
| CVE-2026-58279 | MED 6.5 | microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | 0.6% | — |