IT
57.023 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-33646 HIGH 7.0 microsoft azure_batch Azure Batch Node Agent Elevation of Privilege Vulnerability 0.4%
CVE-2026-57980 MED 5.4 microsoft edge_chromium Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. 0.4%
CVE-2026-23665 HIGH 7.8 microsoft linux_diagnostic_extension Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-62572 HIGH 7.8 microsoft windows_11_24h2 Out-of-bounds read in Application Information Services allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-62571 HIGH 7.8 microsoft windows_10_1607 Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-62467 HIGH 7.8 microsoft windows_10_1809 Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-62464 HIGH 7.8 microsoft windows_10_1809 Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-62462 HIGH 7.8 microsoft windows_10_1809 Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-62461 HIGH 7.8 microsoft windows_10_1809 Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-55233 HIGH 7.8 microsoft windows_10_1809 Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-21262 MED 5.4 microsoft edge_chromium User Interface (UI) Misrepresentation of Critical Information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network 0.4%
CVE-2024-30058 MED 5.4 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.4%
CVE-2026-25165 HIGH 7.8 microsoft windows_10_1607 Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-59229 MED 5.5 microsoft 365_apps Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally. 0.4%
CVE-2025-53791 MED 4.7 microsoft edge_chromium Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. 0.4%
CVE-2023-38176 HIGH 7.0 microsoft azure_arc-enabled_servers Azure Arc-Enabled Servers Elevation of Privilege Vulnerability 0.4%
CVE-2026-45461 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-20865 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-20863 HIGH 7.0 microsoft windows_11_23h2 Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-20842 HIGH 7.0 microsoft windows_10_21h2 Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-20822 HIGH 7.8 microsoft windows_10_1607 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-53769 MED 5.5 microsoft windows_security_app External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally. 0.4%
CVE-2026-24303 CRIT 9.6 microsoft partner_center Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. 0.4%
CVE-2025-47976 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2022-38027 HIGH 7.0 microsoft windows_10 Windows Storage Elevation of Privilege Vulnerability 0.4%