IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-42891 MED 6.5 microsoft edge_chromium User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.3%
CVE-2026-32204 HIGH 7.8 microsoft azure_monitor_agent External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-59187 HIGH 7.8 microsoft windows_10_1507 Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-65680 MED 6.7 microsoft onedrive Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-59131 MED 5.6 microsoft windows_10_1607 No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. 0.3%
CVE-2026-42896 HIGH 7.8 microsoft windows_11_24h2 Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62904 MED 5.4 microsoft edge_chromium Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. 0.3%
CVE-2026-61936 MED 5.5 microsoft windows_10_1809 Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2025-54895 HIGH 7.8 microsoft windows_10_1507 Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-54114 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-54108 HIGH 7.0 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-54105 HIGH 7.0 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-53807 HIGH 7.0 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-49665 HIGH 7.8 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-35199 MED 6.1 microsoft symcrypt SymCrypt is the core cryptographic function library currently used by Windows. From 103.5.0 to before 103.11.0, The SymCryptXmssSign function passes a 64-bit leaf count value to a helper function that accepts a 32-bit parameter. For XMSS^MT parameter sets with 0.3%
CVE-2025-49733 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2023-32010 HIGH 7.0 microsoft windows_11_22h2 Windows Bus Filter Driver Elevation of Privilege Vulnerability 0.3%
CVE-2026-66311 MED 6.2 microsoft edge_chromium Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. 0.3%
CVE-2026-57093 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-56187 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50688 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50674 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50491 HIGH 7.0 microsoft windows_10_1607 Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50490 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50476 HIGH 7.8 microsoft windows_10_1607 Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally. 0.3%