IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-25188 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network. 0.6%
CVE-2025-49698 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2022-22009 HIGH 7.8 microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability 0.6%
CVE-2021-41346 MED 5.3 microsoft windows_10 Console Window Host Security Feature Bypass Vulnerability 0.6%
CVE-2021-40464 HIGH 8.0 microsoft windows_10 Windows Nearby Sharing Elevation of Privilege Vulnerability 0.6%
CVE-2026-23663 HIGH 7.5 microsoft global_secure_access Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. 0.6%
CVE-2026-32177 HIGH 7.3 microsoft .net Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. 0.6%
CVE-2026-26139 HIGH 8.6 microsoft purview Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. 0.6%
CVE-2026-0386 HIGH 7.5 microsoft windows_server_2008 Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network. 0.6%
CVE-2025-47170 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2024-21339 MED 6.4 microsoft windows_10_1809 Windows USB Generic Parent Driver Remote Code Execution Vulnerability 0.6%
CVE-2026-66803 CRIT 10.0 microsoft azure_cosmos_db Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-50659 MED 6.5 microsoft .net Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. 0.5%
CVE-2026-48563 HIGH 7.5 microsoft windows_10_1809 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-47654 HIGH 7.5 microsoft windows_server_2016 Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-32169 CRIT 10.0 microsoft azure_cloud_shell Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2022-22045 HIGH 7.8 microsoft windows_10 Windows.Devices.Picker.dll Elevation of Privilege Vulnerability 0.5%
CVE-2021-38671 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.5%
CVE-2021-38667 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.5%
CVE-2021-31973 HIGH 7.8 microsoft windows_10 Windows GPSVC Elevation of Privilege Vulnerability 0.5%
CVE-2021-31953 HIGH 7.8 microsoft windows_10 Windows Filter Manager Elevation of Privilege Vulnerability 0.5%
CVE-2021-31190 HIGH 7.8 microsoft windows_10 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability 0.5%
CVE-2021-28436 HIGH 7.8 microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability 0.5%
CVE-2021-28351 HIGH 7.8 microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability 0.5%
CVE-2021-28347 HIGH 7.8 microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability 0.5%