IT
56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-54984 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-62211 HIGH 8.7 microsoft dynamics_365 Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. 0.6%
CVE-2025-62210 HIGH 8.7 microsoft dynamics_365 Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. 0.6%
CVE-2025-25008 HIGH 7.1 microsoft windows_server_2016 Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-21414 HIGH 7.0 microsoft windows_10_1507 Windows Core Messaging Elevation of Privileges Vulnerability 0.6%
CVE-2024-20709 MED 5.5 adobe acrobat Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current 0.6%
CVE-2023-32032 MED 6.5 microsoft .net .NET and Visual Studio Elevation of Privilege Vulnerability 0.6%
CVE-2022-29151 HIGH 7.0 microsoft windows_server Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability 0.6%
CVE-2022-29150 HIGH 7.0 microsoft windows_server Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability 0.6%
CVE-2022-29126 HIGH 7.0 microsoft windows_10 Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability 0.6%
CVE-2026-41610 MED 6.3 microsoft visual_studio_code Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0.6%
CVE-2023-21763 HIGH 7.8 microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 0.6%
CVE-2022-21910 HIGH 7.8 microsoft windows_server Microsoft Cluster Port Driver Elevation of Privilege Vulnerability 0.6%
CVE-2025-54908 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-32720 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.6%
CVE-2025-21184 HIGH 7.0 microsoft windows_10_1507 Windows Core Messaging Elevation of Privileges Vulnerability 0.6%
CVE-2025-21234 HIGH 7.8 microsoft windows_10_21h2 Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability 0.6%
CVE-2023-28292 HIGH 7.8 microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability 0.6%
CVE-2023-23402 HIGH 7.8 microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability 0.6%
CVE-2023-23401 HIGH 7.8 microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability 0.6%
CVE-2023-21809 HIGH 7.8 microsoft defender_security_intelligence_updates Microsoft Defender for Endpoint Security Feature Bypass Vulnerability 0.6%
CVE-2023-21714 MED 5.5 microsoft 365_apps Microsoft Office Information Disclosure Vulnerability 0.6%
CVE-2026-26135 CRIT 9.6 microsoft azure_custom_locations_resource_provider Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network. 0.6%
CVE-2026-21261 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2026-21258 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.6%