56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-48804 | MED 6.8 | microsoft windows_10_1507 Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0.6% | — |
| CVE-2025-21357 | MED 6.7 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2024-38246 | HIGH 7.0 | microsoft windows_10_21h2 Win32k Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-28924 | MED 6.7 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2021-34475 | MED 5.4 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-65679 | HIGH 8.1 | microsoft windows_10_1607 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-26150 | HIGH 8.6 | microsoft purview_ediscovery Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-26138 | HIGH 8.6 | microsoft purview Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2023-28298 | MED 5.5 | microsoft windows_10_1607 Windows Kernel Denial of Service Vulnerability | 0.6% | — |
| CVE-2025-53739 | HIGH 7.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-53735 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-50159 | HIGH 7.3 | microsoft windows_10_1507 Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2024-38248 | HIGH 7.0 | microsoft windows_10_21h2 Windows Storage Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-41055 | MED 5.5 | microsoft windows_10 Windows Human Interface Device Information Disclosure Vulnerability | 0.6% | — |
| CVE-2025-26631 | HIGH 7.3 | microsoft visual_studio_code Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-21378 | HIGH 7.8 | microsoft windows_10_1507 Windows CSC Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-21739 | HIGH 7.0 | microsoft windows_10_1507 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-34460 | HIGH 7.8 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-34511 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-34488 | HIGH 7.8 | microsoft windows_10 Windows Console Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-34477 | HIGH 7.8 | microsoft .net_education_bundle_sdk_install_tool Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-50481 | CRIT 9.9 | microsoft azure_active_directory Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-50528 | HIGH 8.2 | microsoft .net Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. | 0.6% | — |
| CVE-2026-26149 | CRIT 9.0 | microsoft power_apps Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2025-64660 | HIGH 8.0 | microsoft visual_studio_code Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network. | 0.6% | — |