57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
Microsoft vulnerabilities
15.483 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-32176 | MED 6.7 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-64661 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-62217 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-68792 | HIGH 7.8 | microsoft 365_apps Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62894 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62771 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62739 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-41100 | MED 4.4 | microsoft 365_copilot Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. | 0.2% | — |
| CVE-2026-40382 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-34338 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-55328 | HIGH 7.8 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-59220 | HIGH 7.0 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-59216 | HIGH 7.0 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62726 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62724 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62723 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-61939 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Winlogon allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-61938 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-61366 | HIGH 7.0 | microsoft windows_10_1607 Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-61346 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-59125 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50472 | HIGH 7.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-42978 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-32089 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-62573 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | 0.2% | — |