IT
56.950 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-21227 HIGH 8.2 microsoft azure_logic_apps Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-20852 HIGH 7.7 microsoft windows_10_1607 Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. 0.5%
CVE-2026-20804 HIGH 7.7 microsoft windows_10_1607 Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. 0.5%
CVE-2022-41095 HIGH 7.8 microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability 0.5%
CVE-2025-59510 MED 5.5 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally. 0.5%
CVE-2023-35347 HIGH 7.1 microsoft windows_10_21h2 Microsoft Install Service Elevation of Privilege Vulnerability 0.5%
CVE-2026-47288 HIGH 7.1 microsoft windows_server_2012 Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network. 0.5%
CVE-2025-54104 MED 6.7 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-53733 HIGH 8.4 microsoft 365_apps Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.5%
CVE-2024-43553 HIGH 7.4 microsoft windows_10_1507 NT OS Kernel Elevation of Privilege Vulnerability 0.5%
CVE-2026-33833 HIGH 8.2 microsoft azure_machine_learning Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2024-43570 MED 6.4 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.5%
CVE-2023-21724 HIGH 7.8 microsoft windows_10_20h2 Microsoft DWM Core Library Elevation of Privilege Vulnerability 0.5%
CVE-2021-40454 MED 5.5 microsoft 365_apps Rich Text Edit Control Information Disclosure Vulnerability 0.5%
CVE-2026-65675 HIGH 7.1 microsoft github_copilot_chat No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network. 0.5%
CVE-2026-47296 HIGH 7.5 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-35429 MED 4.3 microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2025-49667 HIGH 7.8 microsoft windows_10_1507 Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-29975 HIGH 7.8 microsoft pc_manager Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2024-43530 HIGH 7.8 microsoft windows_10_21h2 Windows Update Stack Elevation of Privilege Vulnerability 0.5%
CVE-2024-21397 MED 5.3 microsoft azure_file_sync Microsoft Azure File Sync Elevation of Privilege Vulnerability 0.5%
CVE-2023-32017 HIGH 7.8 microsoft windows_10_1507 Microsoft PostScript Printer Driver Remote Code Execution Vulnerability 0.5%
CVE-2022-35758 MED 5.5 microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability 0.5%
CVE-2023-24862 MED 5.5 microsoft windows_10_1507 Windows Secure Channel Denial of Service Vulnerability 0.5%
CVE-2023-21697 MED 6.2 microsoft windows_10 Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability 0.5%