IT
56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-24489 HIGH 7.8 microsoft windows_server_2016 Cluster Client Failover (CCF) Elevation of Privilege Vulnerability 0.5%
CVE-2025-64655 HIGH 8.8 microsoft dynamics_omnichannel_sdk_storage_containers Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2025-53732 HIGH 7.8 microsoft 365_copilot Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0.5%
CVE-2023-29346 HIGH 7.8 microsoft windows_10_1507 NTFS Elevation of Privilege Vulnerability 0.5%
CVE-2025-29839 MED 4.0 microsoft windows_10_1507 Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2022-38016 HIGH 8.8 microsoft windows_10 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability 0.5%
CVE-2022-37984 HIGH 7.8 microsoft windows_10 Windows WLAN Service Elevation of Privilege Vulnerability 0.5%
CVE-2022-37983 HIGH 7.8 microsoft windows_10 Microsoft DWM Core Library Elevation of Privilege Vulnerability 0.5%
CVE-2025-62201 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-62200 HIGH 7.8 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.5%
CVE-2023-28272 HIGH 7.8 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.5%
CVE-2026-62915 MED 6.5 microsoft exchange_server Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. 0.5%
CVE-2026-61920 MED 6.6 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network. 0.5%
CVE-2026-57106 CRIT 10.0 microsoft purview_data_governance Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2024-20675 MED 6.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability 0.5%
CVE-2023-32053 HIGH 7.8 microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability 0.5%
CVE-2026-49804 MED 6.6 microsoft windows_10_1607 Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack. 0.5%
CVE-2026-58292 HIGH 7.5 microsoft edge_chromium Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2024-41879 HIGH 7.8 adobe acrobat_reader Acrobat Reader versions 127.0.2651.105 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must 0.5%
CVE-2024-28923 MED 6.4 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.5%
CVE-2026-57101 HIGH 7.1 microsoft visual_studio_code Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0.5%
CVE-2026-55139 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.5%
CVE-2025-59204 MED 5.5 microsoft windows_10_1809 Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-55682 MED 6.1 microsoft windows_11_24h2 Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.5%
CVE-2025-55337 MED 6.1 microsoft windows_11_24h2 Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.5%