56.864 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-47953 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2024-38162 | HIGH 7.8 | microsoft azure_connected_machine_agent Azure Connected Machine Agent Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-38153 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-36605 | HIGH 7.4 | microsoft windows_10_1809 Windows Named Pipe Filesystem Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-30224 | HIGH 7.0 | microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-22711 | MED 5.7 | microsoft windows_10 Windows BitLocker Information Disclosure Vulnerability | 0.5% | — |
| CVE-2022-24486 | HIGH 7.8 | microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-21528 | MED 6.5 | microsoft azure_iot_explorer Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2025-62468 | MED 5.5 | microsoft windows_11_23h2 Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2022-37992 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-65801 | CRIT 10.0 | microsoft exchange_online Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-34332 | HIGH 8.0 | microsoft windows_server_2025 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-35431 | CRIT 10.0 | microsoft entra_id Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2025-62203 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-55683 | MED 5.5 | microsoft windows_server_2016 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-54907 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2024-49023 | MED 5.9 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.5% | — |
| CVE-2024-38191 | HIGH 7.8 | microsoft windows_10_1607 Kernel Streaming Service Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-24102 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-50453 | MED 6.1 | microsoft windows_10_1607 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. | 0.5% | — |
| CVE-2026-47639 | MED 5.4 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2026-47636 | MED 5.4 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2026-45465 | MED 5.4 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2026-45464 | MED 5.4 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |
| CVE-2026-45453 | MED 5.4 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 0.5% | — |