56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-54898 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-54896 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-48823 | MED 5.9 | microsoft windows_10_1507 Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2024-43633 | MED 6.5 | microsoft windows_11_22h2 Windows Hyper-V Denial of Service Vulnerability | 0.6% | — |
| CVE-2024-37982 | MED 6.7 | microsoft windows_10_1507 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-37979 | MED 6.7 | microsoft windows_server_2012 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-65770 | CRIT 10.0 | microsoft azure_managed_instance_for_apache_cassandra Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2025-48002 | MED 5.7 | microsoft windows_11_24h2 Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent network. | 0.6% | — |
| CVE-2022-38003 | HIGH 7.8 | microsoft windows_10 Windows Resilient File System Elevation of Privilege | 0.6% | — |
| CVE-2022-37980 | HIGH 7.8 | microsoft windows_10 Windows DHCP Client Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-65806 | MED 6.5 | microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-57977 | HIGH 7.1 | microsoft edge_chromium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-23652 | CRIT 10.0 | microsoft power_pages Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2025-50161 | HIGH 7.3 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2022-23298 | HIGH 7.0 | microsoft windows_10 Windows NT OS Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-23288 | HIGH 7.0 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-23287 | HIGH 7.0 | microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-50683 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network. | 0.6% | — |
| CVE-2025-60714 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2024-38188 | HIGH 7.1 | microsoft azure_network_watcher_agent Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-26213 | HIGH 7.0 | microsoft windows_server_2022_23h2 Microsoft Brokering File System Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-36914 | MED 5.5 | microsoft windows_10_21h2 Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2023-36904 | HIGH 7.8 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-66312 | MED 6.5 | microsoft edge_chromium Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2025-24077 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |