IT
57.056 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-59221 HIGH 7.0 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-47985 HIGH 7.8 microsoft windows_10_1507 Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-24036 HIGH 7.0 microsoft autoupdate Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability 0.4%
CVE-2022-24537 HIGH 7.8 microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability 0.4%
CVE-2026-70318 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-66802 HIGH 8.1 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. 0.4%
CVE-2026-63517 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-50452 HIGH 7.0 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network. 0.4%
CVE-2026-50348 HIGH 7.0 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network. 0.4%
CVE-2026-33822 MED 6.1 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-27925 MED 6.5 microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network. 0.4%
CVE-2023-32055 MED 6.7 microsoft windows_10_1507 Active Template Library Elevation of Privilege Vulnerability 0.4%
CVE-2026-70317 MED 5.5 microsoft 365_apps Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-50510 HIGH 7.8 microsoft github_copilot Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-50482 HIGH 7.3 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. 0.4%
CVE-2026-58640 HIGH 7.3 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. 0.4%
CVE-2026-49790 HIGH 7.3 microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability 0.4%
CVE-2026-49789 HIGH 7.3 microsoft windows_10_1607 Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-26148 HIGH 8.1 microsoft azure_ad_ssh_login_extension_for_linux External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally. 0.4%
CVE-2026-26131 HIGH 7.8 microsoft .net Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-60721 HIGH 7.8 microsoft windows_11_24h2 Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-60716 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-59514 HIGH 7.8 microsoft windows_10_1607 Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2023-33155 HIGH 7.8 microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 0.4%
CVE-2025-62474 HIGH 7.8 microsoft windows_10_1607 Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. 0.4%