| CVE-2026-33821 | 7.7 | high | microsoft / dynamics 365 customer insights | Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate | 116d ago |
| CVE-2026-57985 | 7.6 | high | microsoft / edge chromium | Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over | 64d ago |
| CVE-2026-65681 | 7.5 | high | microsoft / windows 10 1607 | Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a ne | 25d ago |
| CVE-2026-62901 | 7.5 | high | microsoft / visual studio 2022 | Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. | 25d ago |
| CVE-2026-62898 | 7.5 | high | microsoft / visual studio 2022 | Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. | 25d ago |
| CVE-2026-62787 | 7.5 | high | microsoft / windows 10 1607 | Use after free in Windows DNS allows an authorized attacker to execute code over a network. | 25d ago |
| CVE-2026-61363 | 7.5 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network | 25d ago |
| CVE-2026-61352 | 7.5 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Clie | 25d ago |
| CVE-2026-59134 | 7.5 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network | 25d ago |
| CVE-2026-59132 | 7.5 | high | microsoft / windows 10 1607 | Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. | 25d ago |
| CVE-2026-54113 | 7.5 | high | microsoft / windows 10 1607 | Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny ser | 25d ago |
| CVE-2026-62918 | 7.5 | high | microsoft / teams | Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spo | 30d ago |
| CVE-2026-66315 | 7.5 | high | microsoft / edge chromium | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 33d ago |
| CVE-2026-59117 | 7.5 | high | microsoft / terminal | Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. | 51d ago |
| CVE-2026-50651 | 7.5 | high | microsoft / .net | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over | 53d ago |
| CVE-2026-50648 | 7.5 | high | microsoft / .net framework | Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny ser | 53d ago |
| CVE-2026-50527 | 7.5 | high | microsoft / .net framework | Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. | 53d ago |
| CVE-2026-50525 | 7.5 | high | microsoft / .net framework | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over | 53d ago |
| CVE-2026-50524 | 7.5 | high | microsoft / .net | Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service o | 53d ago |
| CVE-2026-47302 | 7.5 | high | microsoft / .net framework | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over | 53d ago |
| CVE-2026-58627 | 7.5 | high | microsoft / windows 10 1607 | Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a ne | 53d ago |
| CVE-2026-58531 | 7.5 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows | 53d ago |
| CVE-2026-57108 | 7.5 | high | microsoft / .net | Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny | 53d ago |
| CVE-2026-57089 | 7.5 | high | microsoft / windows 10 1607 | Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to exec | 53d ago |
| CVE-2026-56648 | 7.5 | high | microsoft / windows 10 1607 | Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to | 53d ago |
| CVE-2026-50685 | 7.5 | high | microsoft / windows 10 1607 | Double free in Windows DHCP Server allows an authorized attacker to execute code over a network. | 53d ago |
| CVE-2026-50647 | 7.5 | high | microsoft / windows 10 1607 | Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an u | 53d ago |
| CVE-2026-50505 | 7.5 | high | microsoft / windows 10 1607 | Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network. | 53d ago |
| CVE-2026-50500 | 7.5 | high | microsoft / windows 10 1607 | Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network. | 53d ago |
| CVE-2026-50496 | 7.5 | high | microsoft / windows 10 1607 | Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information o | 53d ago |
| CVE-2026-50470 | 7.5 | high | microsoft / windows 10 1607 | Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information o | 53d ago |
| CVE-2026-50463 | 7.5 | high | microsoft / windows 10 1809 | Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. | 53d ago |
| CVE-2026-50424 | 7.5 | high | microsoft / windows 11 24h2 | Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a | 53d ago |
| CVE-2026-50414 | 7.5 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allow | 53d ago |
| CVE-2026-50411 | 7.5 | high | microsoft / windows 10 1607 | Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to den | 53d ago |
| CVE-2026-50379 | 7.5 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allow | 53d ago |
| CVE-2026-50368 | 7.5 | high | microsoft / windows 10 1607 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny servic | 53d ago |
| CVE-2026-50355 | 7.5 | high | microsoft / windows 10 1607 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny servic | 53d ago |
| CVE-2026-50330 | 7.5 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a n | 53d ago |
| CVE-2026-50328 | 7.5 | high | microsoft / windows 10 1607 | Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a ne | 53d ago |
| CVE-2026-50304 | 7.5 | high | microsoft / windows 10 1607 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny servic | 53d ago |
| CVE-2026-56170 | 7.5 | high | microsoft / .net | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny servi | 53d ago |
| CVE-2026-54983 | 7.5 | high | microsoft / windows 10 1607 | Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to den | 53d ago |
| CVE-2026-54119 | 7.5 | high | microsoft / windows 10 1607 | Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker | 53d ago |
| CVE-2026-50696 | 7.5 | high | microsoft / windows 10 1809 | Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny | 53d ago |
| CVE-2026-50695 | 7.5 | high | microsoft / windows 10 1607 | Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny servic | 53d ago |
| CVE-2026-50653 | 7.5 | high | microsoft / .net framework | Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker t | 53d ago |
| CVE-2026-50652 | 7.5 | high | microsoft / .net framework | Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a | 53d ago |
| CVE-2026-50506 | 7.5 | high | microsoft / asp.net core odata | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny servi | 53d ago |
| CVE-2026-49788 | 7.5 | high | microsoft / windows 10 1607 | Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service ove | 53d ago |
| CVE-2026-49787 | 7.5 | high | microsoft / windows 10 1607 | Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny s | 53d ago |
| CVE-2026-49181 | 7.5 | high | microsoft / windows 10 1607 | Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privilege | 53d ago |
| CVE-2026-49171 | 7.5 | high | microsoft / windows 10 1607 | Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-47296 | 7.5 | high | microsoft / sql server 2016 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an autho | 53d ago |
| CVE-2026-45646 | 7.5 | high | microsoft / asp.net core odata | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny servi | 53d ago |
| CVE-2026-40378 | 7.5 | high | microsoft / windows 10 1607 | Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows a | 53d ago |
| CVE-2026-58299 | 7.5 | high | microsoft / edge chromium | Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to | 64d ago |
| CVE-2026-58294 | 7.5 | high | microsoft / edge chromium | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 64d ago |
| CVE-2026-58292 | 7.5 | high | microsoft / edge chromium | Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over | 64d ago |
| CVE-2026-58290 | 7.5 | high | microsoft / edge chromium | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unautho | 64d ago |