IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-54109 HIGH 7.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. 0.3%
CVE-2026-50354 HIGH 7.1 microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50318 HIGH 7.8 microsoft windows_10_1607 Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50293 HIGH 7.8 microsoft windows_10_21h2 Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-49800 HIGH 7.8 microsoft windows_10_1809 Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-49795 HIGH 8.8 microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-49793 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. 0.3%
CVE-2026-49792 HIGH 7.8 microsoft windows_10_1607 Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally. 0.3%
CVE-2026-49783 HIGH 7.8 microsoft windows_10_1607 Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-49175 HIGH 7.8 microsoft windows_10_21h2 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-49173 HIGH 7.8 microsoft windows_11_26h1 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-49166 HIGH 7.8 microsoft windows_11_24h2 Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-42982 HIGH 7.8 microsoft windows_10_1607 Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-47635 HIGH 8.4 microsoft office_2024 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0.3%
CVE-2025-53782 HIGH 8.4 microsoft exchange_server Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally. 0.3%
CVE-2025-49726 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Notification allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-49687 HIGH 8.8 microsoft windows_10_1507 Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-21195 MED 6.0 microsoft azure_service_fabric Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-41095 HIGH 7.8 microsoft windows_server_2012 Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-40402 CRIT 9.3 microsoft windows_11_23h2 Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. 0.3%
CVE-2026-40359 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-35415 HIGH 7.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-49738 HIGH 7.8 microsoft pc_manager Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-48819 HIGH 7.1 microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network. 0.3%
CVE-2026-40401 HIGH 7.1 microsoft windows_10_1607 Windows TCP/IP Denial of Service Vulnerability 0.3%