56.801 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-23398 | HIGH 7.1 | microsoft 365_apps Microsoft Excel Spoofing Vulnerability | 0.6% | — |
| CVE-2025-32702 | HIGH 7.8 | microsoft visual_studio_2019 Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2022-35792 | HIGH 7.8 | microsoft windows_10 Storage Spaces Direct Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-28440 | HIGH 7.0 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-59235 | HIGH 7.1 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-29976 | HIGH 7.8 | microsoft sharepoint_server Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2024-49043 | HIGH 7.8 | microsoft sql_server_2016 Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2024-43457 | HIGH 7.8 | microsoft windows_11_24h2 Windows Setup and Deployment Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-1698 | HIGH 7.8 | microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-35422 | MED 6.5 | microsoft windows_10_1607 Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network. | 0.6% | — |
| CVE-2024-21354 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-38163 | HIGH 7.8 | microsoft windows_defender_security_intelligence_updates Windows Defender Attack Surface Reduction Security Feature Bypass | 0.6% | — |
| CVE-2022-38022 | LOW 3.3 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-23257 | HIGH 8.8 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2025-59271 | HIGH 8.7 | microsoft azure_cache_for_redis Redis Enterprise Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-37997 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-49702 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2024-49072 | HIGH 7.8 | microsoft windows_10_1507 Windows Task Scheduler Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-28919 | MED 6.7 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-20669 | MED 6.7 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2023-21572 | MED 6.5 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.6% | — |
| CVE-2021-42304 | MED 6.6 | microsoft azure_real_time_operating_system Azure RTOS Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-42302 | MED 6.6 | microsoft azure_real_time_operating_system Azure RTOS Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-49696 | HIGH 8.4 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2024-38086 | MED 6.4 | microsoft azure_kinect_software_development_kit Azure Kinect SDK Remote Code Execution Vulnerability | 0.6% | — |