IT
57.056 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-47967 MED 4.7 microsoft edge Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2025-29838 HIGH 7.4 microsoft windows_11_24h2 Null pointer dereference in Windows Drivers allows an unauthorized attacker to elevate privileges locally. 0.4%
CVE-2024-49060 HIGH 8.8 microsoft azure_stack_hci Azure Stack HCI Elevation of Privilege Vulnerability 0.4%
CVE-2025-64680 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2024-35265 HIGH 7.0 microsoft windows_10_1809 Windows Perception Service Elevation of Privilege Vulnerability 0.4%
CVE-2026-54128 HIGH 8.4 microsoft windows_10_1607 Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-54122 HIGH 8.4 microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-49798 CRIT 9.3 microsoft windows_10_1607 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. 0.4%
CVE-2026-45474 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-45472 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-45463 HIGH 8.4 microsoft 365_apps Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-26649 HIGH 7.0 microsoft windows_11_22h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-58542 HIGH 7.8 microsoft windows_11_24h2 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-58530 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-50501 HIGH 7.8 microsoft windows_11_24h2 Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-50498 HIGH 7.8 microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability 0.4%
CVE-2026-41614 MED 6.2 microsoft 365_copilot Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally. 0.4%
CVE-2023-36405 HIGH 7.0 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0.4%
CVE-2026-45488 MED 5.4 microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.4%
CVE-2026-45634 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally. 0.4%
CVE-2023-23939 LOW 3.9 microsoft azure_setup_kubectl Azure/setup-kubectl is a GitHub Action for installing Kubectl. This vulnerability only impacts versions before version 3. An insecure temporary creation of a file allows other actors on the Actions runner to replace the Kubectl binary created by this action be 0.4%
CVE-2026-62745 MED 6.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. 0.4%
CVE-2026-62698 HIGH 7.8 microsoft windows_10_1607 Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-62688 HIGH 7.8 microsoft windows_11_24h2 Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-59281 HIGH 7.8 microsoft xbox_gaming_services Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to elevate privileges locally. 0.4%