IT
57.044 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.482 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-38021 HIGH 7.0 microsoft windows_10 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability 0.4%
CVE-2026-48566 MED 5.5 microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-45491 MED 6.2 microsoft .net Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally. 0.4%
CVE-2026-42969 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-42968 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally. 0.4%
CVE-2025-59236 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-62746 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-62743 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-62740 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-62738 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-62730 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-62709 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-62703 MED 5.5 microsoft windows_10_1809 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-61933 MED 5.5 microsoft windows_11_24h2 Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-61360 MED 5.5 microsoft windows_10_1607 Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-61347 MED 5.5 microsoft windows_10_1607 Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-59137 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-59128 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-27906 MED 4.4 microsoft windows_10_21h2 Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally. 0.4%
CVE-2024-26243 HIGH 7.0 microsoft windows_10_21h2 Windows USB Print Driver Elevation of Privilege Vulnerability 0.4%
CVE-2024-26236 HIGH 7.0 microsoft windows_server_2022_23h2 Windows Update Stack Elevation of Privilege Vulnerability 0.4%
CVE-2022-23283 HIGH 7.0 microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability 0.4%
CVE-2026-45466 LOW 3.3 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2025-27735 MED 6.0 microsoft windows_10_1507 Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. 0.4%
CVE-2026-45490 HIGH 7.8 microsoft .net Improper authorization in .NET allows an authorized attacker to elevate privileges locally. 0.4%