IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-63527 HIGH 7.8 microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-50459 HIGH 7.0 microsoft windows_10_21h2 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. 0.3%
CVE-2026-48575 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-48570 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-48568 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-47656 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-45588 HIGH 7.9 microsoft windows_10_1607 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-27913 HIGH 7.7 microsoft windows_server_2012 Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally. 0.3%
CVE-2026-50495 MED 6.1 microsoft windows_10_1809 Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. 0.3%
CVE-2026-50295 MED 5.5 microsoft windows_11_24h2 Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-45494 MED 5.4 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.3%
CVE-2026-45492 MED 5.4 microsoft edge_chromium Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. 0.3%
CVE-2026-42901 CRIT 10.0 microsoft entra_id Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. 0.3%
CVE-2026-49171 HIGH 7.5 microsoft windows_10_1607 Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2022-44669 HIGH 7.0 microsoft windows_10 Windows Error Reporting Elevation of Privilege Vulnerability 0.3%
CVE-2022-41093 HIGH 7.8 microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability 0.3%
CVE-2026-66323 MED 5.4 microsoft edge_chromium Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.3%
CVE-2026-65784 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-32167 MED 6.7 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-23667 HIGH 7.0 microsoft windows_10_1809 Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-20874 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-20873 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-20869 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-20867 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-20866 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. 0.3%