IT
57.056 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-50312 MED 4.7 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-49167 MED 4.7 microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-48569 HIGH 7.1 microsoft visual_studio_code Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0.4%
CVE-2024-26194 HIGH 7.4 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.4%
CVE-2023-35378 HIGH 7.0 microsoft windows_10_1809 Windows Projected File System Elevation of Privilege Vulnerability 0.4%
CVE-2026-40416 MED 4.3 microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.3%
CVE-2026-58647 HIGH 8.0 microsoft power_bi_report_server Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network. 0.3%
CVE-2025-55230 HIGH 7.8 microsoft windows_10_1507 Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2023-21777 HIGH 8.7 microsoft azure_app_service_on_azure_stack Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability 0.3%
CVE-2026-50374 MED 6.3 microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack. 0.3%
CVE-2026-24297 MED 6.5 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows an unauthorized attacker to bypass a security feature over a network. 0.3%
CVE-2025-47179 MED 6.7 microsoft configuration_manager_2403 Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-27475 HIGH 7.0 microsoft windows_11_22h2 Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2024-26242 HIGH 7.0 microsoft windows_10_1507 Windows Telephony Server Elevation of Privilege Vulnerability 0.3%
CVE-2026-68813 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-68808 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-68802 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-68799 MED 5.5 microsoft 365_apps Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-64917 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-64899 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-63531 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-63529 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-63528 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-63524 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-45482 HIGH 8.4 microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0.3%