57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
Microsoft vulnerabilities
15.483 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-32069 | HIGH 7.8 | microsoft windows_10_1809 Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2023-23389 | MED 6.3 | microsoft malware_protection_engine Microsoft Defender Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2022-41086 | MED 6.4 | microsoft windows_10 Windows Group Policy Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2026-54125 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50689 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50677 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50458 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50457 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50427 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50385 | HIGH 8.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50361 | HIGH 7.8 | microsoft windows_11_24h2 Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-50305 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-26183 | HIGH 7.8 | microsoft windows_server_2012 Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-26159 | HIGH 7.8 | microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-62757 | MED 5.3 | microsoft windows_10_1607 Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network. | 0.3% | — |
| CVE-2025-59278 | HIGH 7.8 | microsoft windows_10_1507 Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-59275 | HIGH 7.8 | microsoft windows_10_1507 Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-40418 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-58714 | HIGH 7.8 | microsoft windows_10_1507 Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65799 | MED 6.7 | microsoft windows_10_1607 Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65814 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-32087 | HIGH 7.0 | microsoft windows_10_1607 Heap-based buffer overflow in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-26165 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-45653 | HIGH 7.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-42984 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0.3% | — |