IT
57.056 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-35417 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-25174 HIGH 7.8 microsoft windows_10_1607 Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-55240 HIGH 7.3 microsoft visual_studio_2017 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2023-23412 HIGH 7.8 microsoft windows_10_1507 Windows Accounts Picture Elevation of Privilege Vulnerability 0.3%
CVE-2025-49692 HIGH 7.8 microsoft azure_connected_machine_agent Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-47652 HIGH 8.2 microsoft windows_11_23h2 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. 0.3%
CVE-2026-45604 MED 5.5 microsoft windows_11_23h2 Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-20806 MED 5.5 microsoft windows_10_1809 Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally. 0.3%
CVE-2025-59213 HIGH 8.8 microsoft configuration_manager_2403 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network. 0.3%
CVE-2025-50167 HIGH 7.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-68816 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-64911 HIGH 7.8 microsoft 365_apps Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-64910 HIGH 7.8 microsoft 365_apps Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-64909 HIGH 7.8 microsoft 365_apps Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-64907 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-64903 HIGH 7.8 microsoft 365_apps Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-64898 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-63532 HIGH 7.8 microsoft 365_apps Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-63526 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-66315 HIGH 7.5 microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.3%
CVE-2026-21242 HIGH 7.0 microsoft windows_10_21h2 Use after free in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2022-26828 HIGH 7.0 microsoft windows_10 Windows Bluetooth Driver Elevation of Privilege Vulnerability 0.3%
CVE-2026-55000 MED 6.4 microsoft windows_11_24h2 Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. 0.3%
CVE-2026-40404 HIGH 7.8 microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability 0.3%
CVE-2026-32079 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.3%