IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-50406 HIGH 7.0 microsoft windows_10_21h2 Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50396 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50393 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50390 HIGH 7.0 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50359 HIGH 7.0 microsoft windows_10_1607 Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50358 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Media allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50307 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-54989 HIGH 7.0 microsoft windows_10_1607 Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-54129 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-61367 HIGH 7.8 microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-61365 HIGH 7.8 microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-61364 HIGH 7.8 microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-61356 HIGH 7.8 microsoft windows_10_1809 Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-49742 HIGH 7.8 microsoft windows_10_1507 Integer overflow or wraparound in Microsoft Graphics Component allows an authorized attacker to execute code locally. 0.3%
CVE-2025-49732 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-49725 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Notification allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-70312 MED 5.5 microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-70310 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-68809 MED 5.5 microsoft 365_apps Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-66810 MED 5.5 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2026-66809 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.3%
CVE-2025-62224 MED 5.5 microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network. 0.3%
CVE-2026-56181 HIGH 8.3 microsoft windows_11_24h2 Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. 0.3%
CVE-2023-21542 HIGH 7.0 microsoft windows_10_1607 Windows Installer Elevation of Privilege Vulnerability 0.3%
CVE-2026-41108 HIGH 7.0 microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally. 0.3%