IT
56.864 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-47953 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.5%
CVE-2024-38162 HIGH 7.8 microsoft azure_connected_machine_agent Azure Connected Machine Agent Elevation of Privilege Vulnerability 0.5%
CVE-2024-38153 HIGH 7.8 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.5%
CVE-2023-36605 HIGH 7.4 microsoft windows_10_1809 Windows Named Pipe Filesystem Elevation of Privilege Vulnerability 0.5%
CVE-2022-30224 HIGH 7.0 microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability 0.5%
CVE-2022-22711 MED 5.7 microsoft windows_10 Windows BitLocker Information Disclosure Vulnerability 0.5%
CVE-2022-24486 HIGH 7.8 microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability 0.5%
CVE-2026-21528 MED 6.5 microsoft azure_iot_explorer Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. 0.5%
CVE-2025-62468 MED 5.5 microsoft windows_11_23h2 Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. 0.5%
CVE-2022-37992 HIGH 7.8 microsoft windows_10 Windows Group Policy Elevation of Privilege Vulnerability 0.5%
CVE-2026-65801 CRIT 10.0 microsoft exchange_online Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-34332 HIGH 8.0 microsoft windows_server_2025 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network. 0.5%
CVE-2026-35431 CRIT 10.0 microsoft entra_id Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2025-62203 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-55683 MED 5.5 microsoft windows_server_2016 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-54907 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally. 0.5%
CVE-2024-49023 MED 5.9 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 0.5%
CVE-2024-38191 HIGH 7.8 microsoft windows_10_1607 Kernel Streaming Service Driver Elevation of Privilege Vulnerability 0.5%
CVE-2021-24102 HIGH 7.8 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0.5%
CVE-2026-50453 MED 6.1 microsoft windows_10_1607 Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. 0.5%
CVE-2026-47639 MED 5.4 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2026-47636 MED 5.4 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2026-45465 MED 5.4 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2026-45464 MED 5.4 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2026-45453 MED 5.4 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 0.5%