57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
Microsoft vulnerabilities
15.483 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-70339 | MED 5.4 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.2% | — |
| CVE-2026-65804 | MED 6.1 | microsoft edge_chromium Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.2% | — |
| CVE-2026-62828 | MED 5.4 | microsoft edge Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network. | 0.2% | — |
| CVE-2026-58638 | MED 6.0 | microsoft windows_10_1809 Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. | 0.2% | — |
| CVE-2026-56179 | HIGH 8.3 | microsoft windows_11_24h2 Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. | 0.2% | — |
| CVE-2026-47293 | HIGH 7.0 | microsoft 365_apps Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-45640 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-42911 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-34335 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-26152 | HIGH 7.0 | microsoft windows_10_1607 Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-59195 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally. | 0.2% | — |
| CVE-2025-48813 | MED 6.3 | microsoft windows_10_1809 Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally. | 0.2% | — |
| CVE-2026-56178 | MED 5.5 | microsoft defender_for_endpoint Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-27923 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-26176 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-26170 | HIGH 7.8 | microsoft windows_10_1607 Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-49678 | HIGH 7.0 | microsoft windows_10_1507 Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2025-53788 | HIGH 7.0 | microsoft windows_subsystem_for_linux Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-50526 | HIGH 7.0 | microsoft .net Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally. | 0.2% | — |
| CVE-2026-26181 | HIGH 7.8 | microsoft windows_11_23h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-21221 | HIGH 7.0 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-55013 | HIGH 7.1 | microsoft remote_help Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally. | 0.2% | — |
| CVE-2026-42825 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-65776 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.2% | — |
| CVE-2026-55144 | HIGH 7.1 | microsoft windows_11_24h2 Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally. | 0.2% | — |