57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
Microsoft vulnerabilities
15.483 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-49162 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-48571 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-53135 | HIGH 7.0 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-44818 | HIGH 7.0 | microsoft 365_apps Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.3% | — |
| CVE-2026-44810 | HIGH 8.4 | microsoft windows_11_23h2 Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-34347 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-21237 | HIGH 7.0 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-21234 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65798 | MED 6.7 | microsoft windows_10_1607 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65797 | MED 6.7 | microsoft windows_10_1607 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65795 | MED 6.7 | microsoft windows_10_1607 Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-62883 | MED 6.7 | microsoft windows_10_1607 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-62775 | MED 5.5 | microsoft windows_11_26h1 Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. | 0.3% | — |
| CVE-2026-32155 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-32078 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-32076 | HIGH 7.8 | microsoft windows_11_23h2 Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-48811 | MED 6.7 | microsoft windows_10_1507 Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-48803 | MED 6.7 | microsoft windows_10_1507 Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65774 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65672 | HIGH 7.8 | microsoft windows_11_23h2 Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65671 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-62799 | HIGH 7.8 | microsoft windows_11_26h1 Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50512 | HIGH 7.8 | microsoft pc_manager Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-32074 | HIGH 7.8 | microsoft windows_10_1809 Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-32069 | HIGH 7.8 | microsoft windows_10_1809 Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.3% | — |