IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-50378 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-50321 HIGH 7.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-50317 HIGH 7.8 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-58526 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows Storage allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-54991 HIGH 7.8 microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-54107 HIGH 8.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-32080 HIGH 7.0 microsoft windows_server_2016 Use after free in Windows WalletService allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-20965 HIGH 7.5 microsoft windows_admin_center Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-40420 HIGH 8.8 microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-61928 MED 5.5 microsoft windows_10_1607 Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. 0.2%
CVE-2026-62753 HIGH 7.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-34340 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-33104 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-55696 HIGH 7.8 microsoft windows_10_1809 Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-27910 HIGH 7.8 microsoft windows_10_1607 Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-42912 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-34351 HIGH 7.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-32090 HIGH 7.8 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-24296 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-24295 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-23671 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-34345 HIGH 7.0 microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-32209 MED 4.4 microsoft windows_10_1607 Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally. 0.2%
CVE-2026-27922 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-26182 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.2%