IT
56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-49730 HIGH 7.8 microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-21235 HIGH 7.8 microsoft windows_10_21h2 Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability 0.6%
CVE-2023-23423 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0.6%
CVE-2023-23422 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0.6%
CVE-2022-33640 HIGH 7.8 microsoft open_management_infrastructure System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability 0.6%
CVE-2021-26429 HIGH 7.7 microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability 0.6%
CVE-2026-56192 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2026-55142 MED 5.5 microsoft 365_apps Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2026-55124 MED 5.5 microsoft 365_apps Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2026-55050 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2026-55047 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2026-55028 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2026-55027 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2026-55023 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2026-0391 MED 6.5 microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. 0.6%
CVE-2025-49729 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2024-38016 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0.6%
CVE-2022-44710 HIGH 7.8 microsoft windows_11 DirectX Graphics Kernel Elevation of Privilege Vulnerability 0.6%
CVE-2026-23651 MED 6.7 microsoft aci_confidential_containers Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-24997 MED 4.4 microsoft windows_10_21h2 Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally. 0.6%
CVE-2026-21535 HIGH 8.2 microsoft teams Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network. 0.6%
CVE-2025-59240 MED 5.5 microsoft 365_apps Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2025-59494 HIGH 7.8 microsoft azure_monitor_agent Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-59294 LOW 2.1 microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack. 0.6%
CVE-2025-32721 HIGH 7.3 microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally. 0.6%