56.864 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
Microsoft vulnerabilities
15.479 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-55226 | MED 6.7 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally. | 0.5% | — |
| CVE-2023-36698 | MED 4.4 | microsoft windows_10_1809 Windows Kernel Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2026-62735 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2023-21680 | HIGH 7.8 | microsoft windows_10_1607 Windows Win32k Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-45496 | MED 5.5 | microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0.5% | — |
| CVE-2026-45583 | HIGH 7.5 | microsoft exchange_server Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-20960 | HIGH 8.0 | microsoft power_apps Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2025-21370 | HIGH 7.8 | microsoft windows_11_22h2 Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-42830 | MED 6.5 | microsoft azure_monitor_agent Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-49721 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-32719 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-24068 | MED 5.5 | microsoft windows_10_1507 Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2021-42286 | HIGH 7.8 | microsoft windows_10 Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-42283 | HIGH 8.8 | microsoft windows_10 NTFS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-41377 | HIGH 7.8 | microsoft windows_10 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-41370 | HIGH 7.8 | microsoft windows_10 NTFS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-41367 | HIGH 7.8 | microsoft windows_10 NTFS Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-41366 | HIGH 7.8 | microsoft windows_10 Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36957 | HIGH 7.8 | microsoft windows_10 Windows Desktop Bridge Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-72971 | MED 5.5 | microsoft windows_11_26h1 Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally. | 0.5% | — |
| CVE-2026-55898 | MED 6.1 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0.5% | — |
| CVE-2026-42913 | HIGH 7.5 | microsoft remote_desktop_client Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-33843 | CRIT 9.1 | microsoft entra_id Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2022-44689 | HIGH 7.8 | microsoft windows_10 Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2026-66309 | CRIT 9.1 | microsoft azure_sql_database Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | 0.5% | — |