56.959 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-48808 | MED 5.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-30385 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2024-49025 | MED 5.4 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 0.5% | — |
| CVE-2024-43576 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 0.5% | — |
| CVE-2024-38221 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.5% | — |
| CVE-2024-38093 | MED 4.3 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.5% | — |
| CVE-2024-38082 | MED 4.7 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.5% | — |
| CVE-2024-38083 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.5% | — |
| CVE-2024-30060 | HIGH 7.8 | microsoft azure_monitor_agent Azure Monitor Agent Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-28270 | MED 6.8 | microsoft windows_10_1809 Windows Lock Screen Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2025-60707 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2024-43522 | HIGH 7.0 | microsoft windows_11_22h2 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-26110 | HIGH 8.4 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-53765 | MED 4.4 | microsoft azure_app_service_on_azure_stack Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-50173 | HIGH 7.8 | microsoft windows_10_1507 Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-29970 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-57095 | MED 6.2 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2026-27931 | MED 5.5 | microsoft windows_10_21h2 Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-53800 | HIGH 7.8 | microsoft windows_10_1607 No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2023-28221 | HIGH 7.0 | microsoft windows_10_1507 Windows Error Reporting Service Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-20811 | HIGH 7.8 | microsoft windows_11_23h2 Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-54912 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2024-43585 | MED 5.5 | microsoft windows_10_1809 Code Integrity Guard Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2024-28904 | HIGH 7.8 | microsoft windows_server_2022_23h2 Microsoft Brokering File System Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-35798 | LOW 3.3 | microsoft azure_arc_jumpstart Azure Arc Jumpstart Information Disclosure Vulnerability | 0.5% | — |