IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-61355 HIGH 7.8 microsoft windows_10_21h2 Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-61353 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-59127 HIGH 7.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50310 MED 4.7 microsoft windows_10_1809 Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-33119 MED 5.4 microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.3%
CVE-2023-24920 MED 5.4 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.3%
CVE-2026-33828 HIGH 7.8 microsoft windows_10_1607 Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-33841 HIGH 7.8 microsoft windows_10_21h2 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-21224 HIGH 7.8 microsoft azure_connected_machine_agent Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-49723 HIGH 8.8 microsoft windows_10_1809 Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally. 0.3%
CVE-2026-45654 HIGH 7.9 microsoft windows_11_24h2 Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-20924 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-20918 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-20877 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-62459 HIGH 8.3 microsoft 365_defender_portal Microsoft Defender Portal Spoofing Vulnerability 0.3%
CVE-2026-45501 MED 6.5 microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. 0.3%
CVE-2026-23660 HIGH 7.8 microsoft windows_admin_center Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-66806 MED 5.5 microsoft 365_apps Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-50451 HIGH 7.1 microsoft windows_10_1607 Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-45641 HIGH 8.4 microsoft windows_10_21h2 Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-33098 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-32212 MED 5.5 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-32168 HIGH 7.8 microsoft azure_monitor_agent Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-20831 HIGH 7.8 microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-20826 HIGH 7.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally. 0.3%