IT
56.855 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-26644 MED 5.1 microsoft windows_10_1809 Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally. 0.5%
CVE-2021-36927 HIGH 7.8 microsoft windows_7 Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability 0.5%
CVE-2021-34461 HIGH 7.8 microsoft windows_10 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability 0.5%
CVE-2021-34459 HIGH 7.8 microsoft windows_10 Windows AppContainer Elevation Of Privilege Vulnerability 0.5%
CVE-2021-34455 HIGH 7.8 microsoft windows_10 Windows File History Service Elevation of Privilege Vulnerability 0.5%
CVE-2026-58528 MED 6.8 microsoft windows_10_1809 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. 0.5%
CVE-2026-21259 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally. 0.5%
CVE-2025-62202 HIGH 7.1 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2025-54116 HIGH 7.3 microsoft windows_10_1507 Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-53759 HIGH 7.8 microsoft 365_apps Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5%
CVE-2021-31193 HIGH 7.8 microsoft windows_10 Windows SSDP Service Elevation of Privilege Vulnerability 0.5%
CVE-2026-65816 CRIT 10.0 microsoft azure_web_apps Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-32208 HIGH 8.8 microsoft edge_chromium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network. 0.5%
CVE-2026-21524 HIGH 7.4 microsoft azure_data_explorer Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network. 0.5%
CVE-2026-21521 HIGH 7.4 microsoft 365_word_copilot Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network. 0.5%
CVE-2025-21183 HIGH 7.4 microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability 0.5%
CVE-2025-21182 HIGH 7.4 microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability 0.5%
CVE-2025-21405 HIGH 7.3 microsoft visual_studio_2022 Visual Studio Elevation of Privilege Vulnerability 0.5%
CVE-2023-21815 HIGH 7.8 microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability 0.5%
CVE-2021-38638 HIGH 7.8 microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 0.5%
CVE-2021-38630 HIGH 7.8 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0.5%
CVE-2021-38628 HIGH 7.8 microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 0.5%
CVE-2021-38626 HIGH 7.8 microsoft windows_server_2008 Windows Kernel Elevation of Privilege Vulnerability 0.5%
CVE-2021-38625 HIGH 7.8 microsoft windows_server_2008 Windows Kernel Elevation of Privilege Vulnerability 0.5%
CVE-2021-36974 HIGH 7.8 microsoft windows_10 Windows SMB Elevation of Privilege Vulnerability 0.5%