IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-70339 MED 5.4 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.2%
CVE-2026-65804 MED 6.1 microsoft edge_chromium Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.2%
CVE-2026-62828 MED 5.4 microsoft edge Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network. 0.2%
CVE-2026-58638 MED 6.0 microsoft windows_10_1809 Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. 0.2%
CVE-2026-56179 HIGH 8.3 microsoft windows_11_24h2 Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. 0.2%
CVE-2026-47293 HIGH 7.0 microsoft 365_apps Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-45640 HIGH 7.0 microsoft windows_10_21h2 Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-42911 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-34335 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-26152 HIGH 7.0 microsoft windows_10_1607 Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-59195 HIGH 7.0 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally. 0.2%
CVE-2025-48813 MED 6.3 microsoft windows_10_1809 Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally. 0.2%
CVE-2026-56178 MED 5.5 microsoft defender_for_endpoint Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27923 HIGH 7.8 microsoft windows_10_1607 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-26176 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-26170 HIGH 7.8 microsoft windows_10_1607 Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-49678 HIGH 7.0 microsoft windows_10_1507 Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-50526 HIGH 7.0 microsoft .net Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally. 0.2%
CVE-2026-26181 HIGH 7.8 microsoft windows_11_23h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-21221 HIGH 7.0 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-55013 HIGH 7.1 microsoft remote_help Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally. 0.2%
CVE-2026-42825 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-65776 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-55144 HIGH 7.1 microsoft windows_11_24h2 Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally. 0.2%
CVE-2026-66310 HIGH 7.7 microsoft edge External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. 0.2%