IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-48583 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-44813 HIGH 7.8 microsoft windows_11_26h1 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-44811 HIGH 7.8 microsoft windows_11_26h1 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-44809 HIGH 7.8 microsoft windows_11_24h2 Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-44808 HIGH 7.8 microsoft windows_11_26h1 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-44807 HIGH 7.8 microsoft windows_11_26h1 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-44804 HIGH 7.8 microsoft windows_11_26h1 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-44802 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-21240 HIGH 7.8 microsoft windows_10_1809 Time-of-check time-of-use (toctou) race condition in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50418 MED 5.1 microsoft windows_11_24h2 Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally. 0.3%
CVE-2026-26160 HIGH 7.8 microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-53139 HIGH 7.7 microsoft windows_10_21h2 Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally. 0.3%
CVE-2026-58637 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-58629 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-58619 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-58544 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-56183 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-56173 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50449 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50410 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50397 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50392 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50372 HIGH 7.0 microsoft windows_10_1607 Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50323 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-50296 HIGH 7.0 microsoft windows_10_1607 Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally. 0.3%