IT
56.864 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.479 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-50442 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-50434 MED 5.5 microsoft windows_10_21h2 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-50431 MED 5.5 microsoft windows_10_1607 Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability 0.5%
CVE-2026-50430 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-50409 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-50394 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-50389 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-50352 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-50339 MED 5.5 microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-50334 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-50350 MED 5.5 microsoft windows_10_21h2 Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-50316 MED 5.5 microsoft windows_10_21h2 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-41087 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-34349 MED 5.5 microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-34328 MED 5.5 microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-33842 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. 0.5%
CVE-2026-33117 CRIT 9.1 microsoft azure_sdk_for_java The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, 0.5%
CVE-2025-55231 HIGH 7.5 microsoft windows_server_2012 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2025-21338 HIGH 7.8 microsoft office GDI+ Remote Code Execution Vulnerability 0.5%
CVE-2026-20857 HIGH 7.8 microsoft windows_10_1809 Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 0.5%
CVE-2026-20832 HIGH 7.8 microsoft windows_10_1607 Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability 0.5%
CVE-2025-49680 HIGH 7.3 microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally. 0.5%
CVE-2024-43492 HIGH 7.8 microsoft autoupdate Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability 0.5%
CVE-2023-35363 HIGH 7.8 microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability 0.5%
CVE-2026-20859 HIGH 7.8 microsoft windows_11_24h2 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. 0.5%