IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-44800 HIGH 7.8 microsoft windows_11_23h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-35418 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-32160 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-32159 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-32165 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-32158 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-32083 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-32082 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-65783 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-65782 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-65781 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-65780 HIGH 7.0 microsoft windows_11_24h2 Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62892 HIGH 7.0 microsoft windows_10_1809 Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62774 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62773 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62749 HIGH 7.0 microsoft windows_11_24h2 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-62725 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-34341 HIGH 7.0 microsoft windows_10_1607 Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-42836 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-32153 HIGH 7.8 microsoft windows_10_1809 Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2026-32088 MED 6.1 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Biometric Service allows an unauthorized attacker to bypass a security feature with a physical attack. 0.2%
CVE-2026-20930 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-58720 HIGH 7.8 microsoft windows_10_1809 Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally. 0.2%
CVE-2026-27918 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally. 0.2%
CVE-2025-59497 HIGH 7.0 microsoft defender_for_endpoint Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally. 0.2%