IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-32176 MED 6.7 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2025-62217 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.3%
CVE-2026-68792 HIGH 7.8 microsoft 365_apps Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62894 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62771 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62739 HIGH 7.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-41100 MED 4.4 microsoft 365_copilot Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. 0.2%
CVE-2026-40382 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-34338 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-55328 HIGH 7.8 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-59220 HIGH 7.0 microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-59216 HIGH 7.0 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62726 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62724 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62723 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-61939 HIGH 7.0 microsoft windows_10_1607 Use after free in Winlogon allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-61938 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-61366 HIGH 7.0 microsoft windows_10_1607 Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-61346 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-59125 HIGH 7.0 microsoft windows_10_1607 Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-50472 HIGH 7.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-42978 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-32089 HIGH 7.8 microsoft windows_10_1607 Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-59508 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-59507 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally. 0.2%