IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-63521 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-57989 HIGH 7.4 microsoft edge_chromium Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. 0.3%
CVE-2026-34342 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-53729 HIGH 7.8 microsoft azure_file_sync Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2023-28236 HIGH 7.8 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.3%
CVE-2025-55340 HIGH 7.0 microsoft windows_10_21h2 Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-65777 MED 5.3 microsoft windows_11_23h2 Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network. 0.3%
CVE-2026-62909 HIGH 7.8 microsoft .net Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-32220 MED 4.4 microsoft windows_11_24h2 Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2025-33069 MED 5.1 microsoft windows_11_24h2 Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally. 0.3%
CVE-2026-32072 MED 6.2 microsoft windows_10_1607 Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally. 0.3%
CVE-2023-35362 HIGH 7.8 microsoft windows_10_1507 Windows Clip Service Elevation of Privilege Vulnerability 0.3%
CVE-2023-21733 HIGH 7.0 microsoft windows_10_20h2 Windows Bind Filter Driver Elevation of Privilege Vulnerability 0.3%
CVE-2026-45638 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-45637 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-45605 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-45600 HIGH 7.8 microsoft windows_11_24h2 Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-45593 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows SDK allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-45592 HIGH 7.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-42983 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-42910 HIGH 7.8 microsoft windows_11_24h2 Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-32156 HIGH 7.4 microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code locally. 0.3%
CVE-2026-27924 HIGH 7.8 microsoft windows_10_21h2 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-26153 HIGH 7.8 microsoft windows_10_1809 Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-48000 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. 0.3%