IT
56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-55325 MED 5.5 microsoft windows_10_1507 Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-54915 MED 6.7 microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2024-21304 MED 4.1 microsoft windows_10_1809 Trusted Compute Base Elevation of Privilege Vulnerability 0.5%
CVE-2022-35828 HIGH 7.8 microsoft defender_for_endpoint Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability 0.5%
CVE-2021-41363 MED 4.2 microsoft intune_management_extension Intune Management Extension Security Feature Bypass Vulnerability 0.5%
CVE-2026-59118 CRIT 9.3 microsoft power_apps Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. 0.5%
CVE-2026-50661 MED 6.1 microsoft windows_10_1607 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.5%
CVE-2026-20839 MED 5.5 microsoft windows_10_1607 Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally. 0.5%
CVE-2025-59227 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.5%
CVE-2025-55229 MED 5.3 microsoft windows_10_1507 Improper verification of cryptographic signature in Windows Certificates allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2024-21402 HIGH 7.1 microsoft 365_apps Microsoft Outlook Elevation of Privilege Vulnerability 0.5%
CVE-2023-21726 HIGH 7.8 microsoft windows_10_1607 Windows Credential Manager User Interface Elevation of Privilege Vulnerability 0.5%
CVE-2026-62742 MED 6.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. 0.5%
CVE-2026-62718 MED 6.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. 0.5%
CVE-2026-62715 MED 6.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. 0.5%
CVE-2025-62455 HIGH 7.8 microsoft windows_10_1607 Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2025-50176 HIGH 7.8 microsoft windows_11_22h2 Access of resource using incompatible type ('type confusion') in Graphics Kernel allows an authorized attacker to execute code locally. 0.5%
CVE-2024-38157 HIGH 7.0 microsoft azure_iot_hub_device_client_sdk Azure IoT SDK Remote Code Execution Vulnerability 0.5%
CVE-2022-35762 HIGH 7.8 microsoft windows_10 Storage Spaces Direct Elevation of Privilege Vulnerability 0.5%
CVE-2021-28460 HIGH 8.1 microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability 0.5%
CVE-2026-56184 MED 5.5 microsoft windows_10_21h2 Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-50681 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-50483 MED 5.5 microsoft windows_11_24h2 Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-50473 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-50456 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.5%