IT
56.864 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-62781 HIGH 8.1 microsoft windows_10_1607 Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2025-49722 MED 5.7 microsoft windows_10_1507 Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network. 0.5%
CVE-2022-44697 HIGH 7.8 microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability 0.5%
CVE-2026-44822 HIGH 8.2 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 0.5%
CVE-2025-47989 HIGH 7.0 microsoft azure_connected_machine_agent Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-53740 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-53731 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.5%
CVE-2022-41102 HIGH 7.8 microsoft windows_10 Windows Overlay Filter Elevation of Privilege Vulnerability 0.5%
CVE-2022-41101 HIGH 7.8 microsoft windows_10 Windows Overlay Filter Elevation of Privilege Vulnerability 0.5%
CVE-2022-24549 HIGH 7.8 microsoft windows_10 Windows AppX Package Manager Elevation of Privilege Vulnerability 0.5%
CVE-2026-50338 HIGH 8.2 microsoft azure_spring_cloud Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2025-59500 HIGH 7.7 microsoft azure_notification_service Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2021-1733 HIGH 7.8 microsoft psexec Sysinternals PsExec Elevation of Privilege Vulnerability 0.5%
CVE-2026-65668 HIGH 8.8 microsoft purview_ediscovery Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-62830 CRIT 9.9 microsoft azure_sre_agent Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-20952 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-62209 MED 5.5 microsoft windows_10_1507 Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-62208 MED 5.5 microsoft windows_10_1507 Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-24986 MED 6.5 microsoft azure_promptflow_core Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2022-41077 HIGH 7.8 microsoft windows_10 Windows Fax Compose Form Elevation of Privilege Vulnerability 0.5%
CVE-2022-41114 HIGH 7.0 microsoft windows_10 Windows Bind Filter Driver Elevation of Privilege Vulnerability 0.5%
CVE-2025-47963 MED 6.3 microsoft edge_chromium No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2024-38195 HIGH 7.8 microsoft azure_cyclecloud Azure CycleCloud Remote Code Execution Vulnerability 0.5%
CVE-2024-29986 MED 5.4 microsoft edge_chromium Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability 0.5%
CVE-2026-55121 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.5%