| CVE-2026-55013 | 7.1 | high | microsoft / remote help | Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing | 16d ago |
| CVE-2026-65675 | 7.1 | high | microsoft / github copilot chat | No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a sec | 25d ago |
| CVE-2026-66322 | 7.1 | high | microsoft / edge chromium | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing ove | 33d ago |
| CVE-2026-56171 | 7.1 | high | microsoft / remote desktop web client | Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker t | 50d ago |
| CVE-2026-58529 | 7.1 | high | microsoft / windows 11 26h1 | Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose infor | 53d ago |
| CVE-2026-57101 | 7.1 | high | microsoft / visual studio code | Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows | 53d ago |
| CVE-2026-55122 | 7.1 | high | microsoft / 365 apps | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 53d ago |
| CVE-2026-50682 | 7.1 | high | microsoft / windows 10 21h2 | Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network. | 53d ago |
| CVE-2026-50465 | 7.1 | high | microsoft / windows 11 24h2 | Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally. | 53d ago |
| CVE-2026-50451 | 7.1 | high | microsoft / windows 10 1607 | Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authori | 53d ago |
| CVE-2026-50428 | 7.1 | high | microsoft / windows 11 26h1 | Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to | 53d ago |
| CVE-2026-56193 | 7.1 | high | microsoft / 365 apps | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 53d ago |
| CVE-2026-55144 | 7.1 | high | microsoft / windows 11 24h2 | Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally. | 53d ago |
| CVE-2026-50354 | 7.1 | high | microsoft / windows 10 1607 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-49791 | 7.1 | high | microsoft / windows 10 1607 | Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) | 53d ago |
| CVE-2026-49165 | 7.1 | high | microsoft / windows 10 1607 | Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information | 53d ago |
| CVE-2026-58297 | 7.1 | high | microsoft / edge chromium | Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthor | 64d ago |
| CVE-2026-58296 | 7.1 | high | microsoft / edge chromium | Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthor | 64d ago |
| CVE-2026-57988 | 7.1 | high | microsoft / edge chromium | Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a | 64d ago |
| CVE-2026-57977 | 7.1 | high | microsoft / edge chromium | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-b | 64d ago |
| CVE-2026-48569 | 7.1 | high | microsoft / visual studio code | Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature local | 88d ago |
| CVE-2026-47288 | 7.1 | high | microsoft / windows server 2012 | Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent | 88d ago |
| CVE-2026-45649 | 7.1 | high | microsoft / excel | Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally. | 88d ago |
| CVE-2026-41102 | 7.1 | high | microsoft / powerpoint | Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally. | 116d ago |
| CVE-2026-41101 | 7.1 | high | microsoft / word | Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. | 116d ago |
| CVE-2026-40401 | 7.1 | high | microsoft / windows 10 1607 | Windows TCP/IP Denial of Service Vulnerability | 116d ago |
| CVE-2026-26133 | 7.1 | high | microsoft / 365 copilot | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 173d ago |
| CVE-2026-70307 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privilege | 25d ago |
| CVE-2026-68820exploited | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privilege | 25d ago |
| CVE-2026-65788 | 7 | high | microsoft / windows 11 23h2 | Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-65783 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-65782 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-65781 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-65780 | 7 | high | microsoft / windows 11 24h2 | Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-65779 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-65778 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-65776 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-65678 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-62908 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engi | 25d ago |
| CVE-2026-62897 | 7 | high | microsoft / .net framework | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-62892 | 7 | high | microsoft / windows 10 1809 | Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privilege | 25d ago |
| CVE-2026-62788 | 7 | high | microsoft / windows 11 23h2 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-62780 | 7 | high | microsoft / windows 11 23h2 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-62774 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-62773 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-62766 | 7 | high | microsoft / windows 11 24h2 | Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-62753 | 7 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-62749 | 7 | high | microsoft / windows 11 24h2 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-62748 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony S | 25d ago |
| CVE-2026-62734 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony S | 25d ago |
| CVE-2026-62729 | 7 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony S | 25d ago |
| CVE-2026-62728 | 7 | high | microsoft / windows 10 1607 | Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized at | 25d ago |
| CVE-2026-62726 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-62725 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-62724 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-62723 | 7 | high | microsoft / windows 10 1607 | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-62705 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter | 25d ago |
| CVE-2026-62693 | 7 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Servic | 25d ago |
| CVE-2026-62690 | 7 | high | microsoft / windows 10 1809 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifi | 25d ago |
| CVE-2026-61939 | 7 | high | microsoft / windows 10 1607 | Use after free in Winlogon allows an authorized attacker to elevate privileges locally. | 25d ago |