IT
56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-21833 HIGH 7.8 microsoft windows_10 Virtual Machine IDE Drive Elevation of Privilege Vulnerability 0.6%
CVE-2021-34536 HIGH 7.8 microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability 0.6%
CVE-2021-34445 HIGH 7.8 microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 0.6%
CVE-2021-33773 HIGH 7.8 microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 0.6%
CVE-2025-55320 MED 6.8 microsoft configuration_manager_2403 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network. 0.6%
CVE-2024-43554 MED 5.5 microsoft windows_10_1507 Windows Kernel-Mode Driver Information Disclosure Vulnerability 0.6%
CVE-2024-43509 HIGH 7.8 microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability 0.6%
CVE-2024-30027 HIGH 7.8 microsoft windows_10_1507 NTFS Elevation of Privilege Vulnerability 0.6%
CVE-2024-21431 HIGH 7.8 microsoft windows_10_21h2 Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability 0.6%
CVE-2025-21375 HIGH 7.8 microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability 0.6%
CVE-2025-21367 HIGH 7.8 microsoft windows_10_1809 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability 0.6%
CVE-2024-26250 MED 6.7 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.6%
CVE-2024-26171 MED 6.7 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.6%
CVE-2022-38032 MED 6.6 microsoft windows_10 Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability 0.6%
CVE-2025-47167 HIGH 8.4 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 0.6%
CVE-2026-50524 HIGH 7.5 microsoft .net Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network. 0.6%
CVE-2024-43508 MED 5.5 microsoft windows_11_22h2 Windows Graphics Component Information Disclosure Vulnerability 0.6%
CVE-2024-43500 MED 5.5 microsoft windows_11_22h2 Windows Resilient File System (ReFS) Information Disclosure Vulnerability 0.6%
CVE-2022-21862 HIGH 7.0 microsoft windows_10 Windows Application Model Core API Elevation of Privilege Vulnerability 0.6%
CVE-2022-21859 HIGH 7.0 microsoft windows_10 Windows Accounts Control Elevation of Privilege Vulnerability 0.6%
CVE-2026-62822 HIGH 8.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2025-29979 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2022-22050 HIGH 7.8 microsoft windows_10 Windows Fax Service Elevation of Privilege Vulnerability 0.6%
CVE-2021-33774 HIGH 7.0 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0.6%
CVE-2026-70332 CRIT 9.6 microsoft sharepoint_online Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 0.6%