IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-21537 HIGH 8.8 microsoft defender_for_endpoint Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network. 0.5%
CVE-2026-20833 MED 5.5 microsoft windows_server_2008 Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally. 0.5%
CVE-2023-36403 HIGH 7.0 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.5%
CVE-2022-44678 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.5%
CVE-2022-41050 HIGH 7.8 microsoft windows_10 Windows Extensible File Allocation Table Elevation of Privilege Vulnerability 0.5%
CVE-2025-64677 HIGH 8.2 microsoft office_out-of-box_experience Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2025-53737 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-47977 HIGH 8.2 microsoft nuance_digital_engagement_platform Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2025-32707 HIGH 7.8 microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. 0.5%
CVE-2026-68789 CRIT 9.9 microsoft azure_sql_database Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-62787 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows DNS allows an authorized attacker to execute code over a network. 0.5%
CVE-2025-29978 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-26639 HIGH 7.8 microsoft windows_10_21h2 Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2023-36725 HIGH 7.8 microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability 0.5%
CVE-2022-24530 HIGH 7.8 microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability 0.5%
CVE-2021-43248 HIGH 7.8 microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability 0.5%
CVE-2021-43245 HIGH 7.8 microsoft windows_7 Windows Digital TV Tuner Elevation of Privilege Vulnerability 0.5%
CVE-2021-43223 HIGH 7.8 microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 0.5%
CVE-2026-35425 HIGH 8.0 microsoft azure_api_management Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. 0.5%
CVE-2023-36790 HIGH 7.8 microsoft windows_server_2008 Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability 0.5%
CVE-2022-44679 MED 6.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 0.5%
CVE-2022-44674 MED 5.5 microsoft windows_10 Windows Bluetooth Driver Information Disclosure Vulnerability 0.5%
CVE-2022-41074 MED 5.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 0.5%
CVE-2022-29116 MED 4.7 microsoft windows_11 Windows Kernel Information Disclosure Vulnerability 0.5%
CVE-2021-42322 HIGH 7.8 microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability 0.5%