IT
57.020 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-58641 HIGH 7.8 microsoft .net Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. 0.4%
CVE-2026-50690 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-50455 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-50437 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-50401 MED 5.5 microsoft windows_10_1809 Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-50383 MED 6.1 microsoft windows_10_1809 Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-50341 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-58614 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally. 0.4%
CVE-2026-54997 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-50381 MED 5.5 microsoft windows_10_21h2 Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-50300 MED 5.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-49801 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-40422 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-45594 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-42973 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-42970 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-42906 MED 5.5 microsoft windows_10_21h2 Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. 0.4%
CVE-2025-59188 MED 5.5 microsoft windows_server_2012 Exposure of sensitive information to an unauthorized actor in Windows Failover Cluster allows an authorized attacker to disclose information locally. 0.4%
CVE-2025-59184 MED 5.5 microsoft windows_server_2016 Exposure of sensitive information to an unauthorized actor in Windows High Availability Services allows an authorized attacker to disclose information locally. 0.4%
CVE-2024-26228 HIGH 7.8 microsoft windows_10_1507 Windows Cryptographic Services Security Feature Bypass Vulnerability 0.4%
CVE-2026-20923 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2024-43472 MED 5.8 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 0.4%
CVE-2026-40413 HIGH 7.4 microsoft windows_10_1607 Windows TCP/IP Denial of Service Vulnerability 0.4%
CVE-2025-60720 HIGH 7.8 microsoft windows_10_1607 Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-60713 HIGH 7.8 microsoft windows_server_2016 Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. 0.4%