56.794 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-29821 | MED 5.5 | microsoft dynamics_365_business_central_2023 Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2024-49051 | HIGH 7.8 | microsoft pc_manager Microsoft PC Manager Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-43551 | HIGH 7.8 | microsoft windows_10_1607 Windows Storage Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-38098 | HIGH 7.8 | microsoft azure_connected_machine_agent Azure Connected Machine Agent Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-38141 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-21820 | HIGH 7.4 | microsoft windows_10 Windows Distributed File System (DFS) Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2022-38007 | HIGH 7.8 | microsoft azure_arc Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-43207 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-30377 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-21336 | MED 5.6 | microsoft windows_10_1507 Windows Cryptographic Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-38151 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-38013 | MED 6.7 | microsoft windows_10_1507 Microsoft Windows Server Backup Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-33161 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-33158 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-33149 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2022-34703 | HIGH 7.8 | microsoft windows_10 Windows Partition Management Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-62870 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-40371 | HIGH 8.8 | microsoft dynamics_365 Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-25186 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2023-36883 | MED 4.3 | microsoft edge Microsoft Edge for iOS Spoofing Vulnerability | 0.6% | — |
| CVE-2026-45455 | LOW 3.3 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2024-38122 | MED 5.5 | microsoft windows_10_1507 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-38118 | MED 5.5 | microsoft windows_10_1507 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | 0.6% | — |
| CVE-2022-26788 | HIGH 7.8 | microsoft powershell PowerShell Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-30067 | MED 5.5 | microsoft windows_10_1507 Winlogon Elevation of Privilege Vulnerability | 0.6% | — |