IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-59234 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-47181 HIGH 8.8 microsoft edge_update Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2023-36888 MED 6.3 microsoft edge_chromium Microsoft Edge for Android (Chromium-based) Tampering Vulnerability 0.6%
CVE-2021-40455 MED 5.5 microsoft windows_10 Windows Installer Spoofing Vulnerability 0.6%
CVE-2021-27088 HIGH 7.8 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0.6%
CVE-2026-58284 HIGH 8.3 microsoft edge_chromium Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2023-36737 HIGH 7.8 microsoft azure_network_watcher Azure Network Watcher VM Agent Elevation of Privilege Vulnerability 0.6%
CVE-2023-21541 HIGH 7.8 microsoft windows_10_1607 Windows Task Scheduler Elevation of Privilege Vulnerability 0.6%
CVE-2022-30225 HIGH 7.1 microsoft windows_10 Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability 0.6%
CVE-2025-29796 MED 4.7 microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. 0.6%
CVE-2025-24078 HIGH 7.0 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-21267 MED 4.4 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.6%
CVE-2023-36902 HIGH 7.0 microsoft windows_10_1607 Windows Runtime Remote Code Execution Vulnerability 0.6%
CVE-2026-69400 CRIT 9.6 microsoft azure_logic_apps Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. 0.6%
CVE-2026-62889 HIGH 8.1 microsoft windows_10_1607 Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2025-29811 HIGH 7.8 microsoft windows_11_22h2 Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2024-20695 MED 5.7 microsoft skype_for_business_server Skype for Business Information Disclosure Vulnerability 0.6%
CVE-2022-23255 MED 5.9 microsoft onedrive Microsoft OneDrive for Android Security Feature Bypass Vulnerability 0.6%
CVE-2026-47634 HIGH 7.3 microsoft sharepoint_server Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.6%
CVE-2026-41615 CRIT 9.6 microsoft authenticator Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network. 0.6%
CVE-2026-26120 MED 6.5 microsoft bing Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network. 0.6%
CVE-2026-50426 MED 6.8 microsoft windows_10_1607 Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network. 0.6%
CVE-2026-35438 HIGH 8.3 microsoft windows_admin_center Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network. 0.6%
CVE-2025-26675 HIGH 7.8 microsoft windows_10_21h2 Out-of-bounds read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2023-21694 MED 6.8 microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability 0.6%