56.801 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-24904 | HIGH 7.1 | microsoft windows_server_2008 Windows Installer Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-26128 | HIGH 7.8 | microsoft windows_10_1607 Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-64657 | CRIT 9.8 | microsoft azure_application_gateway Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2025-64656 | CRIT 9.4 | microsoft azure_application_gateway Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2024-43536 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-28269 | MED 6.2 | microsoft windows_10_1507 Windows Boot Manager Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2026-65667 | CRIT 10.0 | microsoft teams Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-40421 | MED 4.3 | microsoft 365_apps Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2026-24304 | CRIT 9.9 | microsoft azure_resource_manager Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2025-59218 | CRIT 9.6 | microsoft entra_id Azure Entra ID Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-29977 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2026-45650 | MED 4.3 | microsoft bing User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2025-49703 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2019-1235 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or commands it receives, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'. | 0.6% | — |
| CVE-2026-55002 | HIGH 8.8 | microsoft sql_server_2016 External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-32183 | HIGH 7.8 | microsoft windows_10_1607 Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-55676 | MED 5.5 | microsoft windows_11_24h2 Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-55244 | CRIT 9.0 | microsoft azure_ai_bot_service Azure Bot Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-21275 | HIGH 7.8 | microsoft windows_10_21h2 Windows App Package Installer Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-43571 | MED 5.6 | microsoft windows_11_24h2 Sudo for Windows Spoofing Vulnerability | 0.6% | — |
| CVE-2022-38017 | MED 6.8 | microsoft storsimple_8010_firmware StorSimple 8000 Series Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-62882 | MED 4.3 | microsoft 365_apps Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2024-43516 | HIGH 7.8 | microsoft windows_10_1507 Windows Secure Kernel Mode Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-21364 | CRIT 9.3 | microsoft azure_site_recovery Microsoft Azure Site Recovery Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-28291 | HIGH 8.4 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 0.6% | — |