57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
Microsoft vulnerabilities
15.483 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-62880 | HIGH 7.8 | microsoft windows_10_1607 Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62877 | HIGH 7.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62876 | HIGH 7.8 | microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62779 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62772 | HIGH 7.8 | microsoft windows_11_26h1 Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62770 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62758 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62755 | HIGH 7.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62736 | HIGH 7.8 | microsoft windows_11_23h2 Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-62733 | HIGH 7.8 | microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-42838 | MED 5.4 | microsoft edge_chromium Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. | 0.2% | — |
| CVE-2026-27920 | HIGH 7.8 | microsoft windows_10_1607 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-27916 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-26184 | HIGH 7.8 | microsoft windows_10_1809 Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-49728 | MED 4.0 | microsoft pc_manager Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security feature locally. | 0.2% | — |
| CVE-2026-49161 | HIGH 7.8 | microsoft pc_manager Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally. | 0.2% | — |
| CVE-2026-0385 | MED 5.0 | microsoft edge_chromium Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | 0.2% | — |
| CVE-2026-61349 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-59189 | HIGH 7.4 | microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-62219 | HIGH 7.0 | microsoft windows_10_1607 Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-62218 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50325 | HIGH 7.0 | microsoft windows_10_1607 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50297 | HIGH 7.0 | microsoft windows_10_1607 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-49805 | HIGH 7.0 | microsoft windows_10_1607 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-58725 | HIGH 7.0 | microsoft windows_10_1507 Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally. | 0.2% | — |