56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-69414 | HIGH 7.8 | microsoft malware_protection_engine Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We wi | 0.6% | — |
| CVE-2023-29333 | LOW 3.3 | microsoft 365_apps Microsoft Access Denial of Service Vulnerability | 0.6% | — |
| CVE-2022-35820 | HIGH 7.8 | microsoft windows_10 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-43240 | HIGH 7.8 | microsoft windows_10 NTFS Set Short Name Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-43230 | HIGH 7.8 | microsoft windows_10 Windows NTFS Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-34456 | HIGH 7.8 | microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-20835 | MED 5.5 | microsoft windows_11_24h2 Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2026-20829 | MED 5.5 | microsoft windows_10_1809 Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2024-30007 | HIGH 8.8 | microsoft windows_server_2022_23h2 Microsoft Brokering File System Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-27096 | HIGH 7.8 | microsoft windows_10 NTFS Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-27091 | HIGH 7.8 | microsoft windows_7 RPC Endpoint Mapper Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-40370 | HIGH 8.8 | microsoft sql_server_2016 External control of file name or path in SQL Server allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-33118 | MED 4.3 | microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2025-59258 | MED 6.2 | microsoft windows_server_2012 Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-21359 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2023-24945 | MED 5.5 | microsoft windows_10_1507 Windows iSCSI Target Service Information Disclosure Vulnerability | 0.6% | — |
| CVE-2023-28263 | MED 5.5 | microsoft visual_studio_2019 Visual Studio Information Disclosure Vulnerability | 0.6% | — |
| CVE-2023-28253 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 0.6% | — |
| CVE-2026-45644 | HIGH 8.0 | microsoft live_share_canvas Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2025-54910 | HIGH 8.4 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2026-20864 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-62565 | HIGH 7.3 | microsoft windows_10_1607 Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-59509 | MED 5.5 | microsoft windows_10_1809 Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2026-69558 | HIGH 8.6 | microsoft partner_center Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-49159 | MED 6.5 | microsoft graph Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. | 0.6% | — |