| CVE-2026-48578 | 7.9 | high | microsoft / windows 10 1607 | Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally. | 88d ago |
| CVE-2026-48576 | 7.9 | high | microsoft / windows 10 1607 | No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 88d ago |
| CVE-2026-48575 | 7.9 | high | microsoft / windows 10 1607 | Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature loc | 88d ago |
| CVE-2026-48573 | 7.9 | high | microsoft / windows 10 1607 | No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 88d ago |
| CVE-2026-48570 | 7.9 | high | microsoft / windows 10 1607 | Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature loc | 88d ago |
| CVE-2026-48568 | 7.9 | high | microsoft / windows 10 1607 | Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature loc | 88d ago |
| CVE-2026-47656 | 7.9 | high | microsoft / windows 10 1607 | Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature lo | 88d ago |
| CVE-2026-45654 | 7.9 | high | microsoft / windows 11 24h2 | Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 88d ago |
| CVE-2026-45588 | 7.9 | high | microsoft / windows 10 1607 | Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature loc | 88d ago |
| CVE-2026-69414 | 7.8 | high | microsoft / malware protection engine | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender p | 22d ago |
| CVE-2026-50523 | 7.8 | high | microsoft / powershell | Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows | 22d ago |
| CVE-2026-70354 | 7.8 | high | microsoft / visual studio 2022 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-70347 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-70346 | 7.8 | high | microsoft / windows 10 1607 | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-70345 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-70344 | 7.8 | high | microsoft / windows 10 1607 | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-70338 | 7.8 | high | microsoft / powershell | Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker | 25d ago |
| CVE-2026-70335 | 7.8 | high | microsoft / visual studio code | Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and V | 25d ago |
| CVE-2026-70313 | 7.8 | high | microsoft / 365 apps | Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information l | 25d ago |
| CVE-2026-70311 | 7.8 | high | microsoft / 365 apps | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-69278 | 7.8 | high | microsoft / visual studio code | Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally | 25d ago |
| CVE-2026-68817 | 7.8 | high | microsoft / 365 apps | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-68816 | 7.8 | high | microsoft / 365 apps | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-68815 | 7.8 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-68814 | 7.8 | high | microsoft / 365 apps | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-68812 | 7.8 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-68811 | 7.8 | high | microsoft / 365 apps | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized att | 25d ago |
| CVE-2026-68810 | 7.8 | high | microsoft / 365 apps | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-68807 | 7.8 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-68806 | 7.8 | high | microsoft / 365 apps | Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-68805 | 7.8 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-68804 | 7.8 | high | microsoft / 365 apps | Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-68803 | 7.8 | high | microsoft / 365 apps | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized att | 25d ago |
| CVE-2026-68801 | 7.8 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-68800 | 7.8 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-68798 | 7.8 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-68796 | 7.8 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-68795 | 7.8 | high | microsoft / 365 apps | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-68794 | 7.8 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-68793 | 7.8 | high | microsoft / 365 apps | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-68792 | 7.8 | high | microsoft / 365 apps | Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an | 25d ago |
| CVE-2026-66807 | 7.8 | high | microsoft / 365 apps | Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-66804 | 7.8 | high | microsoft / windows 10 22h2 | Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locall | 25d ago |
| CVE-2026-66799 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-65814 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges loca | 25d ago |
| CVE-2026-65810 | 7.8 | high | microsoft / .net framework | Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-65790 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-65787 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-65786 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-65775 | 7.8 | high | microsoft / windows 10 1607 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-65774 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-65773 | 7.8 | high | microsoft / windows 10 1809 | Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally. | 25d ago |
| CVE-2026-65673 | 7.8 | high | microsoft / entra connect | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sy | 25d ago |
| CVE-2026-65672 | 7.8 | high | microsoft / windows 11 23h2 | Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locall | 25d ago |
| CVE-2026-65671 | 7.8 | high | microsoft / windows 10 1607 | Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locall | 25d ago |
| CVE-2026-65664 | 7.8 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-65661 | 7.8 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-65657 | 7.8 | high | microsoft / 365 apps | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 25d ago |
| CVE-2026-65656 | 7.8 | high | microsoft / 365 apps | Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an | 25d ago |
| CVE-2026-64920 | 7.8 | high | microsoft / 365 apps | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 25d ago |