| CVE-2026-42977 | 7.8 | high | microsoft / windows 10 1809 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifi | 88d ago |
| CVE-2026-42916 | 7.8 | high | microsoft / windows 10 1607 | Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally | 88d ago |
| CVE-2026-42910 | 7.8 | high | microsoft / windows 11 24h2 | Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges loc | 88d ago |
| CVE-2026-42905 | 7.8 | high | microsoft / windows 10 1607 | Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-42902 | 7.8 | high | microsoft / powertoys | Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-42837 | 7.8 | high | microsoft / windows 10 1809 | Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privile | 88d ago |
| CVE-2026-42829 | 7.8 | high | microsoft / windows 11 24h2 | Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security fea | 88d ago |
| CVE-2026-42828 | 7.8 | high | microsoft / windows 10 1809 | Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privilege | 88d ago |
| CVE-2026-41092 | 7.8 | high | microsoft / windows 10 1607 | Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-40409 | 7.8 | high | microsoft / windows 10 1607 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 88d ago |
| CVE-2026-40404 | 7.8 | high | microsoft / windows 10 1607 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 88d ago |
| CVE-2026-33828 | 7.8 | high | microsoft / windows 10 1607 | Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-42834 | 7.8 | high | microsoft / windows admin center | Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network | 108d ago |
| CVE-2026-41091exploited | 7.8 | high | microsoft / malware protection engine | Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker | 108d ago |
| CVE-2026-42896 | 7.8 | high | microsoft / windows 11 24h2 | Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges loc | 116d ago |
| CVE-2026-42831 | 7.8 | high | microsoft / 365 copilot | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 116d ago |
| CVE-2026-41611 | 7.8 | high | microsoft / visual studio code | Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unau | 116d ago |
| CVE-2026-41095 | 7.8 | high | microsoft / windows server 2012 | Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-41088 | 7.8 | high | microsoft / windows 10 21h2 | Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock all | 116d ago |
| CVE-2026-40419 | 7.8 | high | microsoft / 365 apps | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-40418 | 7.8 | high | microsoft / 365 apps | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-40417 | 7.8 | high | microsoft / dynamics 365 business central | Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-40408 | 7.8 | high | microsoft / windows 10 1607 | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-40407 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privi | 116d ago |
| CVE-2026-40399 | 7.8 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allo | 116d ago |
| CVE-2026-40398 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-40397 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privi | 116d ago |
| CVE-2026-40382 | 7.8 | high | microsoft / windows 10 1607 | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-40381 | 7.8 | high | microsoft / azure connected machine agent | Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges local | 116d ago |
| CVE-2026-40377 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges l | 116d ago |
| CVE-2026-40369 | 7.8 | high | microsoft / windows 11 24h2 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-40362 | 7.8 | high | microsoft / 365 apps | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 116d ago |
| CVE-2026-40360 | 7.8 | high | microsoft / 365 apps | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 116d ago |
| CVE-2026-40359 | 7.8 | high | microsoft / 365 apps | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 116d ago |
| CVE-2026-35421 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally. | 116d ago |
| CVE-2026-35420 | 7.8 | high | microsoft / windows server 2012 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-35418 | 7.8 | high | microsoft / windows 10 1809 | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges local | 116d ago |
| CVE-2026-35417 | 7.8 | high | microsoft / windows 10 1809 | Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-35415 | 7.8 | high | microsoft / windows 10 1607 | Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privi | 116d ago |
| CVE-2026-34351 | 7.8 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allo | 116d ago |
| CVE-2026-34344 | 7.8 | high | microsoft / windows 10 1607 | Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock all | 116d ago |
| CVE-2026-34343 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elev | 116d ago |
| CVE-2026-34338 | 7.8 | high | microsoft / windows 10 1607 | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-34337 | 7.8 | high | microsoft / windows 10 1809 | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges local | 116d ago |
| CVE-2026-34336 | 7.8 | high | microsoft / windows 10 1607 | Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges loc | 116d ago |
| CVE-2026-34334 | 7.8 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allo | 116d ago |
| CVE-2026-34333 | 7.8 | high | microsoft / windows 10 1607 | Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-34330 | 7.8 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GR | 116d ago |
| CVE-2026-33841 | 7.8 | high | microsoft / windows 10 21h2 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-33840 | 7.8 | high | microsoft / windows 11 24h2 | Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-33838 | 7.8 | high | microsoft / windows 10 1607 | Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-33837 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-33835 | 7.8 | high | microsoft / windows 10 1809 | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges local | 116d ago |
| CVE-2026-33834 | 7.8 | high | microsoft / windows 10 1607 | Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges local | 116d ago |
| CVE-2026-32204 | 7.8 | high | microsoft / azure monitor agent | External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges l | 116d ago |
| CVE-2026-66310 | 7.7 | high | microsoft / edge | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose in | 33d ago |
| CVE-2026-32174 | 7.7 | high | microsoft / azure ai bot service | Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. | 79d ago |
| CVE-2026-45497 | 7.7 | high | microsoft / copilot | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an | 93d ago |
| CVE-2026-26147 | 7.7 | high | microsoft / azure stack hci | Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a ne | 106d ago |
| CVE-2026-42832 | 7.7 | high | microsoft / excel | Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. | 116d ago |