56.832 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-30375 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-29957 | MED 6.2 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally. | 0.6% | — |
| CVE-2025-27489 | HIGH 7.8 | microsoft azure_stack_hci_22h2 Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2024-21423 | MED 4.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 0.6% | — |
| CVE-2022-41083 | HIGH 7.8 | microsoft jupyter Visual Studio Code Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-25195 | HIGH 7.8 | microsoft windows_10 Windows PKU2U Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-24103 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-56160 | CRIT 9.1 | microsoft azure_red_hat_openshift Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-32210 | CRIT 9.3 | microsoft dynamics_365 Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2025-24044 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2023-28286 | MED 6.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2022-38043 | MED 5.5 | microsoft windows_10 Windows Security Support Provider Interface Information Disclosure Vulnerability | 0.6% | — |
| CVE-2022-38026 | MED 5.5 | microsoft windows_10 Windows DHCP Client Information Disclosure Vulnerability | 0.6% | — |
| CVE-2022-38025 | MED 5.5 | microsoft windows_11 Windows Distributed File System (DFS) Information Disclosure Vulnerability | 0.6% | — |
| CVE-2022-37996 | MED 5.5 | microsoft windows_10 Windows Kernel Memory Information Disclosure Vulnerability | 0.6% | — |
| CVE-2022-26921 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-26810 | HIGH 7.8 | microsoft windows_10 Windows File Server Resource Management Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-31208 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-62826 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-55135 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-55030 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-55020 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-55019 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-55016 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2025-62552 | HIGH 7.8 | microsoft 365_apps Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 0.6% | — |