IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-65796 HIGH 8.1 microsoft windows_10_1607 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-62873 CRIT 9.8 microsoft windows_admin_center Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-40414 HIGH 7.4 microsoft windows_10_1607 Windows TCP/IP Denial of Service Vulnerability 0.5%
CVE-2025-60704 HIGH 7.5 microsoft windows_10_1607 Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2024-43535 HIGH 7.0 microsoft windows_10_1507 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 0.5%
CVE-2023-21537 HIGH 7.8 microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability 0.5%
CVE-2026-47300 HIGH 8.8 microsoft .net Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-57969 HIGH 8.8 microsoft azure_cyclecloud Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2025-33075 HIGH 7.8 microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2024-43528 HIGH 7.8 microsoft windows_10_1809 Windows Secure Kernel Mode Elevation of Privilege Vulnerability 0.5%
CVE-2023-36759 MED 6.7 microsoft visual_studio_2019 Visual Studio Elevation of Privilege Vulnerability 0.5%
CVE-2023-33152 HIGH 7.0 microsoft 365_apps Microsoft ActiveX Remote Code Execution Vulnerability 0.5%
CVE-2025-33065 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-33063 MED 5.5 microsoft windows_10_1809 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-33061 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-33060 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-33059 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-33058 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-33052 MED 5.5 microsoft windows_10_1809 Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-24069 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2022-30187 MED 4.7 microsoft azure_storage_blobs Azure Storage Library Information Disclosure Vulnerability 0.5%
CVE-2026-65811 HIGH 8.8 microsoft power_bi_report_server Improper input validation in Power BI allows an authorized attacker to execute code over a network. 0.5%
CVE-2026-55145 MED 6.3 microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network. 0.5%
CVE-2026-55122 HIGH 7.1 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2026-40411 CRIT 9.9 microsoft azure_virtual_network_gateway Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network. 0.5%