IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-26828 HIGH 7.0 microsoft windows_10 Windows Bluetooth Driver Elevation of Privilege Vulnerability 0.3%
CVE-2026-55000 MED 6.4 microsoft windows_11_24h2 Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack. 0.3%
CVE-2026-40404 HIGH 7.8 microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability 0.3%
CVE-2026-32079 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.3%
CVE-2023-24899 HIGH 7.0 microsoft windows_11_21h2 Windows Graphics Component Elevation of Privilege Vulnerability 0.3%
CVE-2026-50680 HIGH 8.2 microsoft windows_10_1809 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-49165 HIGH 7.1 microsoft windows_10_1607 Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-45608 MED 6.8 microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-25175 HIGH 7.8 microsoft windows_10_1607 Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-24292 HIGH 7.8 microsoft windows_10_1809 Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-27732 HIGH 7.0 microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-59130 MED 5.6 microsoft windows_10_1607 No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-54992 HIGH 8.4 microsoft windows_10_1607 Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-49184 HIGH 8.4 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. 0.3%
CVE-2025-47993 HIGH 7.8 microsoft windows_11_24h2 Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2022-0280 HIGH 7.5 microsoft windows A race condition vulnerability exists in the QuickClean feature of McAfee Total Protection for Windows prior to 16.0.43 that allows a local user to gain privilege elevation and perform an arbitrary file delete. This could lead to sensitive files being deleted 0.3%
CVE-2026-62897 HIGH 7.0 microsoft .net Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-32193 HIGH 8.8 microsoft azure_kubernetes_service Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally. 0.3%
CVE-2025-54092 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62914 HIGH 7.3 microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. 0.3%
CVE-2026-32172 HIGH 8.0 microsoft power_apps Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network. 0.3%
CVE-2022-34696 HIGH 7.8 microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability 0.3%
CVE-2022-26807 HIGH 7.0 microsoft windows_10 Windows Work Folder Service Elevation of Privilege Vulnerability 0.3%
CVE-2026-62811 HIGH 7.8 microsoft windows_11_23h2 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62797 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. 0.3%