IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-59506 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-55687 HIGH 7.4 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally. 0.2%
CVE-2025-55335 HIGH 7.4 microsoft windows_10_1507 Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally. 0.2%
CVE-2025-49690 HIGH 7.4 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally. 0.2%
CVE-2023-28273 HIGH 7.0 microsoft windows_10_1607 Windows Clip Service Elevation of Privilege Vulnerability 0.2%
CVE-2023-23393 HIGH 7.0 microsoft windows_10_1809 Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability 0.2%
CVE-2026-34336 HIGH 7.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-58543 MED 6.3 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack. 0.2%
CVE-2026-32224 HIGH 7.0 microsoft windows_11_26h1 Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-64661 HIGH 7.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-27468 HIGH 7.0 microsoft windows_10_1507 Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-40410 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-32195 HIGH 7.0 microsoft windows_11_26h1 Stack-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27917 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-26166 HIGH 7.0 microsoft windows_11_23h2 Double free in Windows Shell allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-59196 HIGH 7.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-65773 HIGH 7.8 microsoft windows_10_1809 Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-66318 HIGH 8.1 microsoft edge_chromium Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. 0.2%
CVE-2026-63522 HIGH 7.8 microsoft azure_sql_database Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-62573 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-62469 HIGH 7.0 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-70345 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-65790 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-65786 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62885 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. 0.2%