56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-25188 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network. | 0.6% | — |
| CVE-2025-49698 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2022-22009 | HIGH 7.8 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2021-41346 | MED 5.3 | microsoft windows_10 Console Window Host Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2021-40464 | HIGH 8.0 | microsoft windows_10 Windows Nearby Sharing Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-23663 | HIGH 7.5 | microsoft global_secure_access Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-32177 | HIGH 7.3 | microsoft .net Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2026-26139 | HIGH 8.6 | microsoft purview Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-0386 | HIGH 7.5 | microsoft windows_server_2008 Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network. | 0.6% | — |
| CVE-2025-47170 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2024-21339 | MED 6.4 | microsoft windows_10_1809 Windows USB Generic Parent Driver Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2026-66803 | CRIT 10.0 | microsoft azure_cosmos_db Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-50659 | MED 6.5 | microsoft .net Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2026-48563 | HIGH 7.5 | microsoft windows_10_1809 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-47654 | HIGH 7.5 | microsoft windows_server_2016 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-32169 | CRIT 10.0 | microsoft azure_cloud_shell Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2022-22045 | HIGH 7.8 | microsoft windows_10 Windows.Devices.Picker.dll Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38671 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-38667 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-31973 | HIGH 7.8 | microsoft windows_10 Windows GPSVC Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-31953 | HIGH 7.8 | microsoft windows_10 Windows Filter Manager Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-31190 | HIGH 7.8 | microsoft windows_10 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-28436 | HIGH 7.8 | microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-28351 | HIGH 7.8 | microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-28347 | HIGH 7.8 | microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability | 0.5% | — |