56.807 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-24484 | MED 5.5 | microsoft windows_server_2012 Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability | 0.6% | — |
| CVE-2022-23268 | MED 6.5 | microsoft windows_11 Windows Hyper-V Denial of Service Vulnerability | 0.6% | — |
| CVE-2021-34487 | HIGH 7.0 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-70336 | HIGH 8.8 | microsoft visual_studio_code Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-62795 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-56188 | CRIT 9.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2024-38218 | HIGH 8.4 | microsoft edge_chromium Microsoft Edge (HTML-based) Memory Corruption Vulnerability | 0.6% | — |
| CVE-2023-21531 | HIGH 7.0 | microsoft azure_service_fabric Azure Service Fabric Container Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-34690 | HIGH 7.1 | microsoft windows_10 Windows Fax Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-38142 | HIGH 7.8 | microsoft windows_10_1507 Windows Secure Kernel Mode Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-36569 | HIGH 8.4 | microsoft 365_apps Microsoft Office Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-38039 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-37990 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-29103 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-40361 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-21281 | HIGH 7.8 | microsoft windows_10_1507 Microsoft COM for Windows Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-23395 | LOW 3.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 0.6% | — |
| CVE-2021-27072 | HIGH 7.0 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-68823 | CRIT 9.1 | microsoft azure_confidential_ledger Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-50525 | HIGH 7.5 | microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | 0.6% | — |
| CVE-2025-21403 | MED 6.4 | microsoft on-prem_data_gateway On-Premises Data Gateway Information Disclosure Vulnerability | 0.6% | — |
| CVE-2025-21304 | HIGH 7.8 | microsoft windows_10_1607 Microsoft DWM Core Library Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-43527 | HIGH 7.8 | microsoft windows_11_24h2 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-43514 | HIGH 7.8 | microsoft windows_10_1507 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-38253 | HIGH 7.8 | microsoft windows_11_21h2 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | 0.6% | — |