| CVE-2026-49796 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally. | 53d ago |
| CVE-2026-49793 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code l | 53d ago |
| CVE-2026-49792 | 7.8 | high | microsoft / windows 10 1607 | Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code loc | 53d ago |
| CVE-2026-49783 | 7.8 | high | microsoft / windows 10 1607 | Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass | 53d ago |
| CVE-2026-49176 | 7.8 | high | microsoft / windows 10 1607 | Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally | 53d ago |
| CVE-2026-49175 | 7.8 | high | microsoft / windows 10 21h2 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-49173 | 7.8 | high | microsoft / windows 11 26h1 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-49170 | 7.8 | high | microsoft / windows 10 1809 | Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate | 53d ago |
| CVE-2026-49166 | 7.8 | high | microsoft / windows 11 24h2 | Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-48581 | 7.8 | high | microsoft / surface go 2 1901 firmware | Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privilege | 53d ago |
| CVE-2026-44800 | 7.8 | high | microsoft / windows 11 23h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifi | 53d ago |
| CVE-2026-42982 | 7.8 | high | microsoft / windows 10 1607 | Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to ele | 53d ago |
| CVE-2026-50656 | 7.8 | high | microsoft / malware protection engine | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender p | 81d ago |
| CVE-2026-50512 | 7.8 | high | microsoft / pc manager | Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate priv | 88d ago |
| CVE-2026-50511 | 7.8 | high | microsoft / pc manager | Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attack | 88d ago |
| CVE-2026-49161 | 7.8 | high | microsoft / pc manager | Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally | 88d ago |
| CVE-2026-48583 | 7.8 | high | microsoft / windows 10 1607 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-48574 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-48565 | 7.8 | high | microsoft / windows narrator braille | Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-47292 | 7.8 | high | microsoft / visual studio code | Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to | 88d ago |
| CVE-2026-45658 | 7.8 | high | microsoft / windows 10 1607 | Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally. | 88d ago |
| CVE-2026-45656 | 7.8 | high | microsoft / windows 10 1607 | Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally. | 88d ago |
| CVE-2026-45645 | 7.8 | high | microsoft / 365 apps | Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-45643 | 7.8 | high | microsoft / 365 apps | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-45638 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to eleva | 88d ago |
| CVE-2026-45637 | 7.8 | high | microsoft / windows 10 1809 | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-45636 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-45605 | 7.8 | high | microsoft / windows 10 1607 | Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-45600 | 7.8 | high | microsoft / windows 11 24h2 | Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized | 88d ago |
| CVE-2026-45593 | 7.8 | high | microsoft / windows 10 1809 | Use after free in Windows SDK allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-45592 | 7.8 | high | microsoft / windows 10 1607 | Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileg | 88d ago |
| CVE-2026-45586 | 7.8 | high | microsoft / windows 10 1607 | Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allo | 88d ago |
| CVE-2026-45490 | 7.8 | high | microsoft / .net | Improper authorization in .NET allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-45487 | 7.8 | high | microsoft / windows 10 21h2 | Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized | 88d ago |
| CVE-2026-45486 | 7.8 | high | microsoft / 365 apps | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-45475 | 7.8 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-45471 | 7.8 | high | microsoft / 365 apps | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-45469 | 7.8 | high | microsoft / 365 apps | Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code l | 88d ago |
| CVE-2026-45457 | 7.8 | high | microsoft / 365 apps | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-44824 | 7.8 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-44823 | 7.8 | high | microsoft / 365 apps | Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-44820 | 7.8 | high | microsoft / 365 apps | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-44819 | 7.8 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-44817 | 7.8 | high | microsoft / 365 apps | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized att | 88d ago |
| CVE-2026-44813 | 7.8 | high | microsoft / windows 11 26h1 | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-44812 | 7.8 | high | microsoft / excel | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-44811 | 7.8 | high | microsoft / windows 11 26h1 | Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally | 88d ago |
| CVE-2026-44809 | 7.8 | high | microsoft / windows 11 24h2 | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locall | 88d ago |
| CVE-2026-44808 | 7.8 | high | microsoft / windows 11 26h1 | Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally | 88d ago |
| CVE-2026-44807 | 7.8 | high | microsoft / windows 11 26h1 | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-44804 | 7.8 | high | microsoft / windows 11 26h1 | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-44803 | 7.8 | high | microsoft / excel | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | 88d ago |
| CVE-2026-44802 | 7.8 | high | microsoft / windows 10 1809 | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-42991 | 7.8 | high | microsoft / windows 10 1809 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifi | 88d ago |
| CVE-2026-42989 | 7.8 | high | microsoft / windows 10 1607 | Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevat | 88d ago |
| CVE-2026-42986 | 7.8 | high | microsoft / windows 10 1607 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-42983 | 7.8 | high | microsoft / windows 10 1809 | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-42980 | 7.8 | high | microsoft / windows 10 1607 | Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges | 88d ago |
| CVE-2026-42979 | 7.8 | high | microsoft / windows 10 1809 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifi | 88d ago |
| CVE-2026-42978 | 7.8 | high | microsoft / windows 10 1809 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifi | 88d ago |