VYPR

Vendor CVEs

Microsoft

All CVEs

15,666 total · sorted by risk
  • CVE-2026-21234HigFeb 10, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-21223HigJan 16, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-21221HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-21219HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

  • CVE-2026-20943HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.01

    Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-20869HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20863HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20842HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20836HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20830HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20815HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20814HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-20808HigJan 13, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62573HigDec 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62570HigDec 9, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally.

  • CVE-2025-62569HigDec 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62555HigDec 9, 2025
    risk 0.46cvss 7.0epss 0.01

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-62469HigDec 9, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62219HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62218HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62217HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62213HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.02

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62202HigNov 11, 2025
    risk 0.46cvss 7.1epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2025-60726HigNov 11, 2025
    risk 0.46cvss 7.1epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2025-60719HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.02

    Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60717HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60716HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59515HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59508HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59507HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59506HigNov 11, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59497HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally.

  • CVE-2025-59289HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59285HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.01

    Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59282HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.

  • CVE-2025-59261HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59250HigOct 14, 2025
    risk 0.46cvss 8.1epss 0.01

    Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-59235HigOct 14, 2025
    risk 0.46cvss 7.1epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2025-59232HigOct 14, 2025
    risk 0.46cvss 7.1epss 0.00

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2025-59221HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

  • CVE-2025-59208HigOct 14, 2025
    risk 0.46cvss 7.1epss 0.00

    Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-59205HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59202HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59196HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59195HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally.

  • CVE-2025-59194HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.03

    Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59193HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

  • CVE-2025-58738HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

  • CVE-2025-58737HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally.

  • CVE-2025-58736HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.00

    Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

Page 143 of 314