IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-59192 HIGH 7.8 microsoft windows_10_1507 Buffer over-read in Storport.sys Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-40397 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-25178 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-25171 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-25170 HIGH 7.0 microsoft windows_11_23h2 Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-65046 LOW 3.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.3%
CVE-2025-55678 HIGH 7.0 microsoft windows_10_1507 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2023-35340 HIGH 7.8 microsoft windows_10_1507 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability 0.3%
CVE-2023-24861 HIGH 7.0 microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability 0.3%
CVE-2026-40417 HIGH 7.8 microsoft dynamics_365_business_central Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-33834 HIGH 7.8 microsoft windows_10_1607 Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-23670 MED 5.7 microsoft windows_10_1607 Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2023-33156 MED 6.3 microsoft malware_protection_engine Microsoft Defender Elevation of Privilege Vulnerability 0.3%
CVE-2026-62776 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-68821 HIGH 7.3 microsoft app_installer Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50303 MED 5.5 microsoft windows_10_1809 Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally. 0.3%
CVE-2026-49174 MED 6.1 microsoft windows_10_1809 Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. 0.3%
CVE-2026-34346 MED 5.5 microsoft windows_10_1607 Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. 0.3%
CVE-2025-49762 HIGH 7.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-66799 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-62890 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally. 0.3%
CVE-2026-48578 HIGH 7.9 microsoft windows_10_1607 Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-32075 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-59210 HIGH 7.4 microsoft windows_11_24h2 Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability 0.3%
CVE-2026-65810 HIGH 7.8 microsoft .net_framework Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. 0.3%