IT
56.807 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-38252 HIGH 7.8 microsoft windows_10_1607 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability 0.6%
CVE-2026-70340 HIGH 8.1 microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. 0.6%
CVE-2026-26123 MED 5.5 microsoft authenticator Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2025-47169 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2023-32027 HIGH 7.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 0.6%
CVE-2023-32025 HIGH 7.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 0.6%
CVE-2023-29356 HIGH 7.8 microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability 0.6%
CVE-2023-29349 HIGH 7.8 microsoft odbc_driver_for_sql_server Microsoft ODBC and OLE DB Remote Code Execution Vulnerability 0.6%
CVE-2021-42300 MED 6.0 microsoft azure_sphere Azure Sphere Tampering Vulnerability 0.6%
CVE-2020-1152 MED 5.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system.</p> <p>To exploit the vulnerability, an attacke 0.6%
CVE-2026-47653 HIGH 8.8 microsoft windows_10_1607 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2025-29834 HIGH 7.5 microsoft edge_chromium Out-of-bounds read in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2022-22023 MED 6.6 microsoft windows_10 Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability 0.6%
CVE-2026-42823 CRIT 9.9 microsoft azure_logic_apps Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. 0.6%
CVE-2025-27739 HIGH 7.8 microsoft windows_10_1809 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-27731 HIGH 7.8 microsoft windows_10_1809 Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-27730 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-27476 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-27467 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-26674 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. 0.6%
CVE-2025-26666 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally. 0.6%
CVE-2025-21337 LOW 3.3 microsoft windows_10_1507 Windows NTFS Elevation of Privilege Vulnerability 0.6%
CVE-2022-37979 HIGH 7.8 microsoft windows_10 Windows Hyper-V Elevation of Privilege Vulnerability 0.6%
CVE-2021-33761 HIGH 7.8 microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 0.6%
CVE-2026-65791 CRIT 9.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. 0.6%