IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-49734 HIGH 7.0 microsoft powershell Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-47975 HIGH 7.0 microsoft windows_10_1507 Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-69543 HIGH 8.5 microsoft azure_virtual_machines Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network. 0.3%
CVE-2026-70307 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-65673 HIGH 7.8 microsoft entra_connect Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50488 HIGH 7.8 microsoft windows_11_24h2 Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-58635 HIGH 7.8 microsoft windows_10_1809 Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-59241 HIGH 7.8 microsoft windows_11_24h2 Improper link resolution before file access ('link following') in Windows Health and Optimized Experiences Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-47182 MED 5.6 microsoft edge_chromium Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2024-21355 HIGH 7.0 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability 0.3%
CVE-2026-59119 HIGH 7.3 microsoft powershell Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-32077 HIGH 7.8 microsoft windows_10_1607 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-49685 HIGH 7.0 microsoft windows_10_1809 Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-59135 MED 5.5 microsoft windows_10_1607 Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-35420 HIGH 7.8 microsoft windows_server_2012 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-32222 HIGH 7.8 microsoft windows_11_24h2 Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-32070 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-62569 HIGH 7.0 microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-59215 HIGH 7.0 microsoft windows_11_24h2 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-55228 HIGH 7.8 microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. 0.3%
CVE-2025-55224 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. 0.3%
CVE-2022-24482 HIGH 7.0 microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability 0.3%
CVE-2026-45656 HIGH 7.8 microsoft windows_10_1607 Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-45642 LOW 3.9 microsoft windows_10_1607 Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack. 0.3%
CVE-2026-41088 HIGH 7.8 microsoft windows_10_21h2 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.3%