IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-54898 HIGH 7.8 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-54896 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-48823 MED 5.9 microsoft windows_10_1507 Cryptographic issues in Windows Cryptographic Services allows an unauthorized attacker to disclose information over a network. 0.6%
CVE-2024-43633 MED 6.5 microsoft windows_11_22h2 Windows Hyper-V Denial of Service Vulnerability 0.6%
CVE-2024-37982 MED 6.7 microsoft windows_10_1507 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability 0.6%
CVE-2024-37979 MED 6.7 microsoft windows_server_2012 Windows Kernel Elevation of Privilege Vulnerability 0.6%
CVE-2026-65770 CRIT 10.0 microsoft azure_managed_instance_for_apache_cassandra Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2025-48002 MED 5.7 microsoft windows_11_24h2 Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent network. 0.6%
CVE-2022-38003 HIGH 7.8 microsoft windows_10 Windows Resilient File System Elevation of Privilege 0.6%
CVE-2022-37980 HIGH 7.8 microsoft windows_10 Windows DHCP Client Elevation of Privilege Vulnerability 0.6%
CVE-2026-65806 MED 6.5 microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. 0.6%
CVE-2026-57977 HIGH 7.1 microsoft edge_chromium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.6%
CVE-2026-23652 CRIT 10.0 microsoft power_pages Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2025-50161 HIGH 7.3 microsoft windows_10_1507 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2022-23298 HIGH 7.0 microsoft windows_10 Windows NT OS Kernel Elevation of Privilege Vulnerability 0.6%
CVE-2022-23288 HIGH 7.0 microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability 0.6%
CVE-2022-23287 HIGH 7.0 microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability 0.6%
CVE-2026-50683 HIGH 8.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network. 0.6%
CVE-2025-60714 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally. 0.6%
CVE-2024-38188 HIGH 7.1 microsoft azure_network_watcher_agent Azure Network Watcher VM Agent Elevation of Privilege Vulnerability 0.6%
CVE-2024-26213 HIGH 7.0 microsoft windows_server_2022_23h2 Microsoft Brokering File System Elevation of Privilege Vulnerability 0.6%
CVE-2023-36914 MED 5.5 microsoft windows_10_21h2 Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability 0.6%
CVE-2023-36904 HIGH 7.8 microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 0.6%
CVE-2026-66312 MED 6.5 microsoft edge_chromium Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. 0.6%
CVE-2025-24077 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%