| CVE-2026-55052 | 8.8 | high | microsoft / sharepoint server | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a ne | 53d ago |
| CVE-2026-54121 | 8.8 | high | microsoft / windows 10 1607 | Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate p | 53d ago |
| CVE-2026-50692 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50687 | 8.8 | high | microsoft / windows 11 24h2 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50670 | 8.8 | high | microsoft / windows 10 1809 | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50666 | 8.8 | high | microsoft / windows 10 1607 | Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges ove | 53d ago |
| CVE-2026-50489 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50477 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50474 | 8.8 | high | microsoft / windows 10 1607 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 53d ago |
| CVE-2026-50444 | 8.8 | high | microsoft / windows 10 1607 | Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to ele | 53d ago |
| CVE-2026-50438 | 8.8 | high | microsoft / pc manager | Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attack | 53d ago |
| CVE-2026-50413 | 8.8 | high | microsoft / windows 11 24h2 | Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-50398 | 8.8 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allow | 53d ago |
| CVE-2026-50385 | 8.8 | high | microsoft / windows 11 24h2 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime all | 53d ago |
| CVE-2026-50382 | 8.8 | high | microsoft / windows 10 1809 | Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally. | 53d ago |
| CVE-2026-50370 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent | 53d ago |
| CVE-2026-50369 | 8.8 | high | microsoft / windows 10 1607 | Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a netwo | 53d ago |
| CVE-2026-50360 | 8.8 | high | microsoft / windows 10 21h2 | Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevat | 53d ago |
| CVE-2026-47295 | 8.8 | high | microsoft / sql server 2016 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an autho | 53d ago |
| CVE-2026-58608 | 8.8 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spool | 53d ago |
| CVE-2026-57969 | 8.8 | high | microsoft / azure cyclecloud | Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileg | 53d ago |
| CVE-2026-55005 | 8.8 | high | microsoft / exchange server | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a netwo | 53d ago |
| CVE-2026-55002 | 8.8 | high | microsoft / sql server 2016 | External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a net | 53d ago |
| CVE-2026-54999 | 8.8 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allo | 53d ago |
| CVE-2026-54982 | 8.8 | high | microsoft / windows 10 1607 | Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized atta | 53d ago |
| CVE-2026-54107 | 8.8 | high | microsoft / windows 10 1607 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allo | 53d ago |
| CVE-2026-50663 | 8.8 | high | microsoft / age of empires ii | Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute c | 53d ago |
| CVE-2026-50342 | 8.8 | high | microsoft / windows 11 24h2 | Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally | 53d ago |
| CVE-2026-49795 | 8.8 | high | microsoft / windows 10 1809 | Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 53d ago |
| CVE-2026-49178 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over | 53d ago |
| CVE-2026-48564 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. | 53d ago |
| CVE-2026-47632 | 8.8 | high | microsoft / azure connected machine agent | Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privil | 53d ago |
| CVE-2026-57981 | 8.8 | high | microsoft / edge chromium | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 64d ago |
| CVE-2026-57974 | 8.8 | high | microsoft / edge chromium | Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code | 64d ago |
| CVE-2026-56645 | 8.8 | high | microsoft / edge chromium | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over | 64d ago |
| CVE-2026-54998 | 8.8 | high | microsoft / exchange online | Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a ne | 65d ago |
| CVE-2026-47645 | 8.8 | high | microsoft / 365 copilot | Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorize | 78d ago |
| CVE-2026-32208 | 8.8 | high | microsoft / edge chromium | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows | 78d ago |
| CVE-2026-47653 | 8.8 | high | microsoft / windows 10 1607 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 88d ago |
| CVE-2026-47289 | 8.8 | high | microsoft / windows app | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network | 88d ago |
| CVE-2026-45648 | 8.8 | high | microsoft / windows server 2022 | Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over | 88d ago |
| CVE-2026-45504 | 8.8 | high | microsoft / exchange server | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privilege | 88d ago |
| CVE-2026-45484 | 8.8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileg | 88d ago |
| CVE-2026-42985 | 8.8 | high | microsoft / remote desktop client | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 88d ago |
| CVE-2026-40371 | 8.8 | high | microsoft / dynamics 365 | Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an auth | 88d ago |
| CVE-2026-32193 | 8.8 | high | microsoft / azure kubernetes service | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Servi | 88d ago |
| CVE-2026-45659exploited | 8.8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 106d ago |
| CVE-2026-35430 | 8.8 | high | microsoft / azure privileged identity management | Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorize | 106d ago |
| CVE-2026-45495 | 8.8 | high | microsoft / edge chromium | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 110d ago |
| CVE-2026-41613 | 8.8 | high | microsoft / visual studio code | Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | 116d ago |
| CVE-2026-41109 | 8.8 | high | microsoft / visual studio code | Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copil | 116d ago |
| CVE-2026-41094 | 8.8 | high | microsoft / data formulator | Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized atta | 116d ago |
| CVE-2026-41086 | 8.8 | high | microsoft / windows admin center | Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network | 116d ago |
| CVE-2026-40420 | 8.8 | high | microsoft / 365 apps | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 116d ago |
| CVE-2026-40403 | 8.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally. | 116d ago |
| CVE-2026-40370 | 8.8 | high | microsoft / sql server 2016 | External control of file name or path in SQL Server allows an authorized attacker to execute code over a network. | 116d ago |
| CVE-2026-40365 | 8.8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 116d ago |
| CVE-2026-40357 | 8.8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 116d ago |
| CVE-2026-35439 | 8.8 | high | microsoft / sharepoint server | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code ove | 116d ago |
| CVE-2026-35436 | 8.8 | high | microsoft / 365 apps | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 116d ago |