IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-53788 HIGH 7.0 microsoft windows_subsystem_for_linux Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-66325 MED 6.1 microsoft edge_chromium Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.2%
CVE-2026-33101 HIGH 7.8 microsoft windows_11_24h2 Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-42832 HIGH 7.7 microsoft excel Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. 0.2%
CVE-2026-33103 MED 5.5 microsoft dynamics_365 Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally. 0.2%
CVE-2026-32214 MED 5.5 microsoft windows_10_1607 Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. 0.2%
CVE-2025-59289 HIGH 7.0 microsoft windows_10_21h2 Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-40381 HIGH 7.8 microsoft azure_connected_machine_agent Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-35436 HIGH 8.8 microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-59288 MED 5.3 microsoft playwright Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network. 0.2%
CVE-2026-47648 HIGH 7.0 microsoft windows_10_1607 Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-57973 MED 6.3 microsoft windows_subsystem_for_linux Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally. 0.2%
CVE-2026-50523 HIGH 7.8 microsoft powershell Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally. 0.2%
CVE-2026-47304 HIGH 8.1 microsoft .net Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. 0.2%
CVE-2026-45647 MED 5.5 microsoft defender_for_endpoint Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-65779 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-65778 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-65678 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62777 HIGH 7.8 microsoft windows_10_1607 Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-42976 HIGH 7.8 microsoft windows_10_1607 Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-58527 HIGH 7.8 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-50676 HIGH 7.8 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-50673 HIGH 7.8 microsoft windows_10_1607 Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-50667 HIGH 7.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-50440 HIGH 7.8 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally. 0.2%