IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.469 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-25184 HIGH 7.0 microsoft windows_11_23h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-55945 MED 4.2 microsoft edge_chromium Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally. 0.2% —
CVE-2025-59261 HIGH 7.0 microsoft windows_11_22h2 Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2025-59193 HIGH 7.0 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-20930 HIGH 7.8 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2025-49737 HIGH 7.0 microsoft teams Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2025-59205 HIGH 7.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2025-58727 HIGH 7.0 microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2025-49756 LOW 3.3 microsoft 365_apps Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized attacker to bypass a security feature locally. 0.2% —
CVE-2026-85892 HIGH 7.8 microsoft edge_chromium Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-81355 HIGH 7.5 microsoft windows_10_1607 Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to execute code locally. 0.2% —
CVE-2026-78464 HIGH 7.0 microsoft windows_11_24h2 Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-77894 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-73005 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-69859 HIGH 7.0 microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-69799 HIGH 7.8 microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-69779 HIGH 7.0 microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows Win32K allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-69682 HIGH 7.0 microsoft windows_10_1809 Use after free in Windows Host Guardian Service allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-69581 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-69563 HIGH 7.0 microsoft windows_10_1607 Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-69466 HIGH 7.0 microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-69448 HIGH 7.0 microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-69441 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-69440 HIGH 7.0 microsoft windows_11_24h2 Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally. 0.2% —
CVE-2026-69404 HIGH 7.0 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. 0.2% —