IT
56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-21362 MED 5.5 microsoft windows_10_1507 Windows Kernel Security Feature Bypass Vulnerability 0.4%
CVE-2026-32081 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-20949 HIGH 7.8 microsoft 365_apps Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. 0.4%
CVE-2025-59243 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-55236 HIGH 7.3 microsoft windows_10_1809 Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally. 0.4%
CVE-2025-29842 HIGH 7.5 microsoft windows_10_1507 Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security feature over a network. 0.4%
CVE-2025-24049 HIGH 8.4 microsoft azure_command-line_interface Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally. 0.4%
CVE-2023-21804 HIGH 7.8 microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability 0.4%
CVE-2026-70335 HIGH 7.8 microsoft visual_studio_code Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. 0.4%
CVE-2026-68798 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-41611 HIGH 7.8 microsoft visual_studio_code Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-41134 HIGH 7.8 microsoft kiota Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/query parameter mappings 0.4%
CVE-2026-32215 MED 5.5 microsoft windows_10_1809 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-24282 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. 0.4%
CVE-2025-26684 MED 6.7 microsoft defender_for_endpoint External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2024-49059 HIGH 7.0 microsoft 365_apps Microsoft Office Elevation of Privilege Vulnerability 0.4%
CVE-2026-41090 CRIT 9.3 microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. 0.4%
CVE-2026-32217 MED 5.5 microsoft windows_10_1607 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. 0.4%
CVE-2025-59203 MED 5.5 microsoft windows_10_1507 Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally. 0.4%
CVE-2025-59197 MED 5.5 microsoft windows_10_1507 Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally. 0.4%
CVE-2025-53730 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-32704 HIGH 8.4 microsoft 365_apps Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2024-21381 MED 6.8 microsoft azure_active_directory Microsoft Azure Active Directory B2C Spoofing Vulnerability 0.4%
CVE-2026-58286 HIGH 8.1 microsoft edge_chromium Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2026-58282 HIGH 8.1 microsoft edge_chromium Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.4%