IT
57.056 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Microsoft vulnerabilities

15.483 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-62807 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-62803 HIGH 7.8 microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-45459 LOW 3.3 microsoft 365_apps Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. 0.4%
CVE-2026-59136 MED 5.5 microsoft windows_10_1607 Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-57085 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally. 0.4%
CVE-2026-50469 HIGH 7.8 microsoft windows_10_1809 Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-50454 HIGH 7.8 microsoft windows_11_24h2 Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-50438 HIGH 8.8 microsoft pc_manager Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-58636 HIGH 7.8 microsoft pc_manager Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-58525 HIGH 8.2 microsoft edge_chromium Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. 0.4%
CVE-2026-45460 MED 4.7 microsoft 365_apps Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally. 0.4%
CVE-2026-25176 HIGH 7.8 microsoft windows_10_1607 Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2026-40358 HIGH 8.4 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2025-59290 HIGH 7.8 microsoft windows_10_21h2 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-58716 HIGH 8.8 microsoft windows_10_1507 Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-58715 HIGH 8.8 microsoft windows_10_1507 Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2025-55322 HIGH 7.3 microsoft omniparser Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network. 0.4%
CVE-2024-54138 MED 6.1 microsoft nugetgallery NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately 0.4%
CVE-2021-41334 HIGH 7.0 microsoft windows_10 Windows Desktop Bridge Elevation of Privilege Vulnerability 0.4%
CVE-2025-47968 HIGH 7.8 microsoft autoupdate Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. 0.4%
CVE-2024-21417 HIGH 8.8 microsoft windows_10_1809 Windows Text Services Framework Elevation of Privilege Vulnerability 0.4%
CVE-2023-21566 HIGH 7.8 microsoft visual_studio_2017 Visual Studio Elevation of Privilege Vulnerability 0.4%
CVE-2026-45602 CRIT 9.1 microsoft windows_10_1607 No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. 0.4%
CVE-2026-32216 MED 5.5 microsoft windows_11_26h1 Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally. 0.4%
CVE-2026-20809 HIGH 7.8 microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. 0.4%