56.832 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-37983 | MED 6.7 | microsoft windows_10_1507 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-37976 | MED 6.7 | microsoft windows_10_1507 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2026-69519 | HIGH 8.6 | microsoft azure_stack_hci Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2024-29052 | HIGH 7.8 | microsoft windows_10_21h2 Windows Storage Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-21866 | HIGH 7.0 | microsoft windows_10 Windows System Launcher Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-40477 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-60726 | HIGH 7.1 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2022-37995 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-57105 | HIGH 8.0 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2024-30071 | MED 4.7 | microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-26239 | HIGH 7.8 | microsoft windows_10_1507 Windows Telephony Server Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-23411 | MED 6.5 | microsoft windows_10_1507 Windows Hyper-V Denial of Service Vulnerability | 0.6% | — |
| CVE-2023-21678 | HIGH 7.8 | microsoft windows_10_1607 Windows Print Spooler Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-21559 | MED 5.5 | microsoft windows_10_1809 Windows Cryptographic Information Disclosure Vulnerability | 0.6% | — |
| CVE-2023-21550 | MED 5.5 | microsoft windows_10_1809 Windows Cryptographic Information Disclosure Vulnerability | 0.6% | — |
| CVE-2023-21540 | MED 5.5 | microsoft windows_10_1809 Windows Cryptographic Information Disclosure Vulnerability | 0.6% | — |
| CVE-2022-26795 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-62819 | HIGH 8.1 | microsoft windows_10_1607 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | 0.6% | — |
| CVE-2026-26147 | HIGH 7.7 | microsoft azure_stack_hci Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-32207 | HIGH 8.8 | microsoft azure_machine_learning Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2025-54904 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-54903 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-54902 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-54900 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-54899 | HIGH 7.8 | microsoft 365_apps Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |