Microsoft
Products: .NET · ASP.NET Core · Azure Kubernetes Service · Azure Migrate · Microsoft .NET Framework · Microsoft 365 Apps for Enterprise · Microsoft Azure Functions · Microsoft Configuration Manager · Microsoft Dataverse · Microsoft Defender for IoT · Microsoft Edge (Chromium-based) · Microsoft Entra · Microsoft Exchange Server 2016 Cumulative Update 23 · Microsoft Exchange Server 2019 Cumulative Update 13 · Microsoft Exchange Server 2019 Cumulative Update 14 · Microsoft Exchange Server 2019 Cumulative Update 15 · Microsoft Exchange Server Subscription Edition RTM · Microsoft ODBC Driver 17 for SQL Server on Linux · Microsoft ODBC Driver 17 for SQL Server on MacOS · Microsoft ODBC Driver 17 for SQL Server on Windows
544.8
Score
39
CVEs
15
Active
24
PoC
15
KEV
#3
Rank
| CVE ID | CVSS | Exploit | Score(hover) | Affected Products |
|---|---|---|---|---|
| CVE-2026-49336 | 5.5v4.0 | POC | 0.0 | kiota-typescript |
| CVE-2026-46402 | 8.1v3.1 | POC | 0.0 | UFO |
| CVE-2026-46414 | 8.8v3.1 | POC | 0.0 | UFO |
| CVE-2026-46416 | 6.3v3.1 | POC | 0.0 | UFO |
| CVE-2026-46544 | 5.3v3.1 | POC | 0.0 | UFO |
| CVE-2026-32201 | 6.5v3.1 | ACTIVE | 40.6 | Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019Microsoft SharePoint Server Subscription Edition |
| CVE-2026-24888 | 6.5v3.1 | POC | 0.0 | maker.js |
| CVE-2026-20963 | 9.8v3.1 | ACTIVE | 40.6 | Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019Microsoft SharePoint Server Subscription Edition |
| CVE-2025-55315 | 9.9v3.1 | POC | 0.0 | ASP.NET CoreMicrosoft Visual Studio 2022 version 17.10Microsoft Visual Studio 2022 version 17.12Microsoft Visual Studio 2022 version 17.14 |
| CVE-2025-59287 | 9.8v3.1 | ACTIVE | 40.6 | Windows Server 2012Windows Server 2012 (Server Core installation)Windows Server 2012 R2Windows Server 2012 R2 (Server Core installation)Windows Server 2016Windows Server 2016 (Server Core installation)Windows Server 2019Windows Server 2019 (Server Core installation)Windows Server 2022Windows Server 2022, 23H2 Edition (Server Core installation) |
| CVE-2025-54914 | 10.0v3.1 | POC | 0.0 | Networking |
| CVE-2025-55241 | 10.0v3.1 | POC | 0.0 | Microsoft Entra |
| CVE-2025-50165 | 9.8v3.1 | POC | 0.0 | Windows 11 Version 24H2Windows Server 2025Windows Server 2025 (Server Core installation) |
| CVE-2025-53770 | 9.8v3.1 | ACTIVE | 40.6 | Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019Microsoft SharePoint Server Subscription Edition |
| CVE-2025-49704 | 8.8v3.1 | ACTIVE | 26.4 | Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019 |
| CVE-2025-49706 | 6.5v3.1 | ACTIVE | 31.2 | Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019Microsoft SharePoint Server Subscription Edition |
| CVE-2025-7326 | 7.0v3.1 | POC | 0.0 | ASP.NET CoreMicrosoft.AspNetCore.App.Runtime.linux-armMicrosoft.AspNetCore.App.Runtime.linux-arm64Microsoft.AspNetCore.App.Runtime.linux-musl-armMicrosoft.AspNetCore.App.Runtime.linux-musl-arm64Microsoft.AspNetCore.App.Runtime.linux-musl-x64Microsoft.AspNetCore.App.Runtime.linux-x64Microsoft.AspNetCore.App.Runtime.osx-arm64Microsoft.AspNetCore.App.Runtime.osx-x64Microsoft.AspNetCore.App.Runtime.win-arm |
| CVE-2025-33073 | 8.8v3.1 | ACTIVE | 26.4 | Windows 10 Version 1507Windows 10 Version 1607Windows 10 Version 1809Windows 10 Version 21H2Windows 10 Version 22H2Windows 11 version 22H2Windows 11 version 22H3Windows 11 Version 23H2Windows 11 Version 24H2Windows Server 2008 R2 Service Pack 1 |
| CVE-2025-24989 | 8.2v3.1 | ACTIVE | 31.2 | Microsoft Power Pages |
| CVE-2025-21298 | 9.8v3.1 | POC | 0.0 | Windows 10 Version 1507Windows 10 Version 1607Windows 10 Version 1809Windows 10 Version 21H2Windows 10 Version 22H2Windows 11 version 22H2Windows 11 version 22H3Windows 11 Version 23H2Windows 11 Version 24H2Windows Server 2008 R2 Service Pack 1 |
| CVE-2024-49040 | 7.5v3.1 | POC | 0.0 | Microsoft Exchange Server 2016 Cumulative Update 23Microsoft Exchange Server 2019 Cumulative Update 13Microsoft Exchange Server 2019 Cumulative Update 14 |
| CVE-2024-38139 | 8.7v3.1 | POC | 0.0 | Microsoft Dataverse |
| CVE-2024-38190 | 8.6v3.1 | POC | 0.0 | Microsoft Power Platform |
| CVE-2024-38204 | 7.5v3.1 | POC | 0.0 | Microsoft Azure Functions |
| CVE-2024-43468 | 9.8v3.1 | ACTIVE | 40.6 | Microsoft Configuration Manager |
| CVE-2024-38063 | 9.8v3.1 | POC | 0.0 | Windows 10 Version 1507Windows 10 Version 1607Windows 10 Version 1809Windows 10 Version 21H2Windows 10 Version 22H2Windows 11 version 21H2Windows 11 version 22H2Windows 11 version 22H3Windows 11 Version 23H2Windows 11 Version 24H2 |
| CVE-2024-38094 | 7.2v3.1 | ACTIVE | 24.0 | Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019Microsoft SharePoint Server Subscription Edition |
| CVE-2024-30053 | 6.5v3.1 | POC | 0.0 | Azure Migrate |
| CVE-2024-29053 | 8.8v3.1 | POC | 0.0 | Microsoft Defender for IoT |
| CVE-2024-29059 | 7.5v3.1 | ACTIVE | 40.6 | Microsoft .NET Framework |
| CVE-2024-21392 | 7.5v3.1 | POC | 0.0 | .NETMicrosoft Visual Studio 2022 version 17.4Microsoft Visual Studio 2022 version 17.6Microsoft Visual Studio 2022 version 17.8Microsoft Visual Studio 2022 version 17.9PowerShell 7.3PowerShell 7.4 |
| CVE-2024-21400 | 9.0v3.1 | POC | 0.0 | Azure Kubernetes Service |
| CVE-2024-21404 | 7.5v3.1 | POC | 0.0 | .NETMicrosoft Visual Studio 2022 version 17.4Microsoft Visual Studio 2022 version 17.6Microsoft Visual Studio 2022 version 17.8 |
| CVE-2024-21410 | 9.8v3.1 | ACTIVE | 40.6 | Microsoft Exchange Server 2016 Cumulative Update 23Microsoft Exchange Server 2019 Cumulative Update 13Microsoft Exchange Server 2019 Cumulative Update 14 |
| CVE-2024-21413 | 9.8v3.1 | ACTIVE | 40.6 | Microsoft 365 Apps for EnterpriseMicrosoft Office 2016Microsoft Office 2019Microsoft Office LTSC 2021 |
| CVE-2023-36038 | 8.2v3.1 | POC | 0.0 | .NETASP.NET CoreMicrosoft Visual Studio 2022 version 17.2Microsoft Visual Studio 2022 version 17.4Microsoft Visual Studio 2022 version 17.6Microsoft Visual Studio 2022 version 17.7 |
| CVE-2023-41763 | 5.3v3.1 | ACTIVE | 40.6 | Skype for Business Server 2015 CU13Skype for Business Server 2019 CU7 |
| CVE-2023-36873 | 7.4v3.1 | POC | 0.0 | Microsoft .NET Framework |
| CVE-2023-38180 | 7.5v3.1 | ACTIVE | 40.6 | .NETASP.NET CoreMicrosoft Visual Studio 2022 version 17.2Microsoft Visual Studio 2022 version 17.4Microsoft Visual Studio 2022 version 17.6 |