IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-62750 MED 6.5 microsoft windows_10_1607 Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network. 0.6%
CVE-2026-55035 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2025-58718 HIGH 8.8 microsoft remote_desktop_client Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2025-47969 MED 4.4 microsoft windows_11_22h2 Exposure of sensitive information to an unauthorized actor in Windows Hello allows an authorized attacker to disclose information locally. 0.6%
CVE-2023-28249 MED 6.2 microsoft windows_10_1507 Windows Boot Manager Security Feature Bypass Vulnerability 0.6%
CVE-2025-47980 MED 6.2 microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information locally. 0.6%
CVE-2024-43450 HIGH 7.5 microsoft windows_server_2008 Windows DNS Spoofing Vulnerability 0.6%
CVE-2025-24995 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2026-55134 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2026-55132 HIGH 7.8 microsoft 365_apps Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2026-55130 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2026-55128 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2026-55127 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2026-55125 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0.6%
CVE-2026-55055 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2026-55038 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2026-55033 HIGH 7.8 microsoft 365_apps Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2026-55032 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-59211 MED 5.5 microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally. 0.6%
CVE-2025-59186 MED 5.5 microsoft windows_server_2016 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. 0.6%
CVE-2025-55336 MED 5.5 microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally. 0.6%
CVE-2025-48800 MED 6.8 microsoft windows_10_1507 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.6%
CVE-2025-48003 MED 6.8 microsoft windows_10_1809 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.6%
CVE-2024-38022 HIGH 7.0 microsoft windows_10_1507 Windows Image Acquisition Elevation of Privilege Vulnerability 0.6%
CVE-2024-30069 MED 4.7 microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability 0.6%