IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-32170 MED 6.7 microsoft windows_10_1607 Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-21530 MED 6.7 microsoft windows_10_1607 Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-20853 HIGH 7.4 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally. 0.3%
CVE-2026-44814 MED 5.5 microsoft windows_11_26h1 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-0390 MED 6.7 microsoft windows_10_1607 Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-32149 HIGH 7.3 microsoft windows_10_1607 Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. 0.3%
CVE-2026-70330 MED 6.7 microsoft windows_10_1607 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-70304 MED 6.7 microsoft windows_10_1607 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62708 MED 6.4 microsoft windows_11_24h2 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack. 0.3%
CVE-2026-33115 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-33114 HIGH 8.4 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.3%
CVE-2025-21401 MED 4.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability 0.3%
CVE-2025-26665 HIGH 7.0 microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows upnphost.dll allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-34344 HIGH 7.8 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-59253 MED 5.5 microsoft windows_10_1507 Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally. 0.3%
CVE-2025-55690 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-21191 HIGH 7.0 microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-53134 HIGH 7.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-65662 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-62798 MED 5.5 microsoft windows_11_23h2 Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-62796 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-62793 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-62786 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-70347 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-70346 HIGH 7.8 microsoft windows_10_1607 Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. 0.3%