IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-58650 HIGH 7.8 microsoft visual_studio_code Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. 0.3%
CVE-2026-50650 HIGH 7.8 microsoft .net Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. 0.3%
CVE-2025-59191 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50375 MED 6.3 microsoft windows_10_1809 Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62834 CRIT 9.3 microsoft azure_data_factory Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. 0.3%
CVE-2026-70354 HIGH 7.8 microsoft .net Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. 0.3%
CVE-2025-55691 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-55688 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-55684 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-32196 MED 6.1 microsoft windows_admin_center Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. 0.3%
CVE-2026-41102 HIGH 7.1 microsoft powerpoint Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally. 0.3%
CVE-2026-41101 HIGH 7.1 microsoft word Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. 0.3%
CVE-2026-34339 MED 5.5 microsoft windows_10_1607 Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally. 0.3%
CVE-2026-32221 HIGH 8.4 microsoft windows_11_24h2 Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-32198 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-26141 HIGH 7.8 microsoft azure_automation_hybrid_worker_windows_extension Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-55223 HIGH 7.0 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-54913 HIGH 7.8 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62812 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-56174 HIGH 7.8 microsoft windows_10_1809 Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-42902 HIGH 7.8 microsoft powertoys Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-42829 HIGH 7.8 microsoft windows_11_24h2 Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-41092 HIGH 7.8 microsoft windows_10_1607 Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-32199 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-32197 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.3%