IT
56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-48808 MED 5.5 microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-30385 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2024-49025 MED 5.4 microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability 0.5%
CVE-2024-43576 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 0.5%
CVE-2024-38221 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.5%
CVE-2024-38093 MED 4.3 microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.5%
CVE-2024-38082 MED 4.7 microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.5%
CVE-2024-38083 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.5%
CVE-2024-30060 HIGH 7.8 microsoft azure_monitor_agent Azure Monitor Agent Elevation of Privilege Vulnerability 0.5%
CVE-2023-28270 MED 6.8 microsoft windows_10_1809 Windows Lock Screen Security Feature Bypass Vulnerability 0.5%
CVE-2025-60707 HIGH 7.8 microsoft windows_10_1809 Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2024-43522 HIGH 7.0 microsoft windows_11_22h2 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability 0.5%
CVE-2026-26110 HIGH 8.4 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-53765 MED 4.4 microsoft azure_app_service_on_azure_stack Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-50173 HIGH 7.8 microsoft windows_10_1507 Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-29970 HIGH 7.8 microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2026-57095 MED 6.2 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally. 0.5%
CVE-2026-27931 MED 5.5 microsoft windows_10_21h2 Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2025-53800 HIGH 7.8 microsoft windows_10_1607 No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2023-28221 HIGH 7.0 microsoft windows_10_1507 Windows Error Reporting Service Elevation of Privilege Vulnerability 0.5%
CVE-2026-20811 HIGH 7.8 microsoft windows_11_23h2 Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-54912 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2024-43585 MED 5.5 microsoft windows_10_1809 Code Integrity Guard Security Feature Bypass Vulnerability 0.5%
CVE-2024-28904 HIGH 7.8 microsoft windows_server_2022_23h2 Microsoft Brokering File System Elevation of Privilege Vulnerability 0.5%
CVE-2022-35798 LOW 3.3 microsoft azure_arc_jumpstart Azure Arc Jumpstart Information Disclosure Vulnerability 0.5%