IT
57.020 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-59505 HIGH 7.8 microsoft windows_10_1607 Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-48001 MED 6.8 microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.4%
CVE-2025-29795 HIGH 7.8 microsoft edge_update Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-50657 MED 4.7 microsoft defender_for_endpoint Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-58278 MED 5.4 microsoft edge_chromium Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2023-21524 HIGH 7.8 microsoft windows_10_1607 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability 0.4%
CVE-2026-42893 HIGH 7.4 microsoft outlook Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network. 0.4%
CVE-2025-49714 HIGH 7.8 microsoft python Trust boundary violation in Visual Studio Code - Python extension allows an unauthorized attacker to execute code locally. 0.4%
CVE-2024-30031 HIGH 7.8 microsoft windows_10_1507 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability 0.4%
CVE-2026-33838 HIGH 7.8 microsoft windows_10_1607 Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-33102 CRIT 9.3 microsoft 365_copilot Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. 0.4%
CVE-2025-49731 LOW 3.1 microsoft teams Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network. 0.4%
CVE-2025-21372 HIGH 7.8 microsoft windows_11_24h2 Microsoft Brokering File System Elevation of Privilege Vulnerability 0.4%
CVE-2024-38207 MED 6.3 microsoft edge_chromium Microsoft Edge (HTML-based) Memory Corruption Vulnerability 0.4%
CVE-2022-24540 HIGH 7.0 microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability 0.4%
CVE-2026-42909 HIGH 7.5 microsoft remote_desktop_client Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.4%
CVE-2023-21771 HIGH 7.0 microsoft windows_10 Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability 0.4%
CVE-2026-62871 HIGH 7.8 microsoft .net Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-59255 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-59207 HIGH 7.8 microsoft windows_10_1809 Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-58728 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-55677 HIGH 7.8 microsoft windows_11_24h2 Untrusted pointer dereference in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-55339 HIGH 7.8 microsoft windows_11_22h2 Out-of-bounds read in Windows NDIS allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-50175 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-50152 HIGH 7.8 microsoft windows_10_1507 Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.4%