IT
57.044 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.482 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-27930 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2024-21405 HIGH 7.0 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability 0.4%
CVE-2023-33163 HIGH 7.5 microsoft windows_server_2008 Windows Network Load Balancing Remote Code Execution Vulnerability 0.4%
CVE-2026-45606 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally. 0.4%
CVE-2026-42915 MED 5.5 microsoft windows_10_21h2 Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally. 0.4%
CVE-2026-40366 HIGH 8.4 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-40363 HIGH 8.4 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2026-32154 HIGH 7.8 microsoft windows_11_23h2 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-24283 HIGH 8.8 microsoft windows_11_24h2 Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-23673 HIGH 7.8 microsoft windows_10_1607 Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-60711 MED 6.3 microsoft edge_chromium Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.4%
CVE-2025-54919 HIGH 7.5 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally. 0.4%
CVE-2025-27488 MED 6.7 microsoft windows_hardware_lab_kit Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2023-28246 HIGH 7.8 microsoft windows_11_21h2 Windows Registry Elevation of Privilege Vulnerability 0.4%
CVE-2024-21337 MED 5.2 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 0.4%
CVE-2026-61925 HIGH 7.8 microsoft windows_10_1607 Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-59242 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-55701 HIGH 7.8 microsoft windows_10_1507 Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-55695 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally. 0.4%
CVE-2025-53137 HIGH 7.0 microsoft windows_10_1507 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-62721 HIGH 7.8 microsoft windows_10_1607 Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-62712 HIGH 7.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-49791 HIGH 7.1 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-50158 HIGH 7.0 microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-65785 MED 6.5 microsoft windows_11_24h2 Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network. 0.4%