56.832 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-49054 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.6% | — |
| CVE-2023-36008 | MED 6.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-21759 | LOW 3.3 | microsoft windows_10 Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2025-53795 | CRIT 9.1 | microsoft pc_manager Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2025-47168 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2022-37999 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Preference Client Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-37994 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Preference Client Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-37993 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Preference Client Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-27064 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Installer Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-42987 | HIGH 8.1 | microsoft windows_server_2012 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2020-17163 | HIGH 7.8 | microsoft python Visual Studio Code Python Extension Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-36729 | HIGH 7.8 | microsoft windows_10_1507 Named Pipe File System Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-33762 | HIGH 7.0 | microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-70326 | HIGH 8.8 | microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-20851 | MED 6.2 | microsoft windows_11_24h2 Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-59282 | HIGH 7.0 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-21345 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2025-53774 | MED 6.5 | microsoft 365_copilot_chat Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | 0.6% | — |
| CVE-2025-21374 | MED 5.5 | microsoft windows_10_1507 Windows CSC Service Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-20691 | MED 4.7 | microsoft windows_10_1507 Windows Themes Information Disclosure Vulnerability | 0.6% | — |
| CVE-2022-41123 | HIGH 7.8 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-28237 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2022-21896 | HIGH 7.0 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-41348 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-30376 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |