57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
Microsoft vulnerabilities
15.483 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-42891 | MED 6.5 | microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.3% | — |
| CVE-2026-32204 | HIGH 7.8 | microsoft azure_monitor_agent External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-59187 | HIGH 7.8 | microsoft windows_10_1507 Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65680 | MED 6.7 | microsoft onedrive Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-59131 | MED 5.6 | microsoft windows_10_1607 No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-42896 | HIGH 7.8 | microsoft windows_11_24h2 Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-62904 | MED 5.4 | microsoft edge_chromium Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0.3% | — |
| CVE-2026-61936 | MED 5.5 | microsoft windows_10_1809 Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. | 0.3% | — |
| CVE-2025-54895 | HIGH 7.8 | microsoft windows_10_1507 Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-54114 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-54108 | HIGH 7.0 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-54105 | HIGH 7.0 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-53807 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-49665 | HIGH 7.8 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-35199 | MED 6.1 | microsoft symcrypt SymCrypt is the core cryptographic function library currently used by Windows. From 103.5.0 to before 103.11.0, The SymCryptXmssSign function passes a 64-bit leaf count value to a helper function that accepts a 32-bit parameter. For XMSS^MT parameter sets with | 0.3% | — |
| CVE-2025-49733 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2023-32010 | HIGH 7.0 | microsoft windows_11_22h2 Windows Bus Filter Driver Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2026-66311 | MED 6.2 | microsoft edge_chromium Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. | 0.3% | — |
| CVE-2026-57093 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-56187 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50688 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50674 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50491 | HIGH 7.0 | microsoft windows_10_1607 Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50490 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50476 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally. | 0.3% | — |