Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-62798 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62796 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62793 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62786 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62775 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62746 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62743 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62740 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62738 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62730 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62709 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally. | ||
| CVE-2026-62703 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | ||
| CVE-2026-61936 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-61933 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | ||
| CVE-2026-61928 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. | ||
| CVE-2026-61360 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally. | ||
| CVE-2026-61347 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally. | ||
| CVE-2026-59137 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally. | ||
| CVE-2026-59136 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally. | ||
| CVE-2026-59135 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally. | ||
| CVE-2026-59131 | Med | 0.36 | 5.6 | 0.00 | Aug 11, 2026 | No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. | ||
| CVE-2026-59130 | Med | 0.36 | 5.6 | 0.00 | Aug 11, 2026 | No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally. | ||
| CVE-2026-59128 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally. | ||
| CVE-2026-54123 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally. | ||
| CVE-2026-49177 | Med | 0.36 | 5.5 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally. | ||
| CVE-2026-48566 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-45647 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-45634 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally. | ||
| CVE-2026-45606 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally. | ||
| CVE-2026-45604 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally. | ||
| CVE-2026-45594 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally. | ||
| CVE-2026-44821 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-44814 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | ||
| CVE-2026-44805 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally. | ||
| CVE-2026-42973 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. | ||
| CVE-2026-42972 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally. | ||
| CVE-2026-42971 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. | ||
| CVE-2026-42970 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. | ||
| CVE-2026-42969 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. | ||
| CVE-2026-42968 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally. | ||
| CVE-2026-42906 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. | ||
| CVE-2026-41612 | Med | 0.36 | 5.5 | 0.01 | May 12, 2026 | Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-35440 | Med | 0.36 | 5.5 | 0.00 | May 12, 2026 | Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-35419 | Med | 0.36 | 5.5 | 0.00 | May 12, 2026 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. | ||
| CVE-2026-34339 | Med | 0.36 | 5.5 | 0.00 | May 12, 2026 | Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally. | ||
| CVE-2026-32185 | Med | 0.36 | 5.5 | 0.00 | May 12, 2026 | Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally. | ||
| CVE-2026-33103 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally. | ||
| CVE-2026-32218 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2026-32217 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2026-32216 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally. |
- risk 0.36cvss 5.5epss 0.00
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
- risk 0.36cvss 5.5epss 0.00
Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.6epss 0.00
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.6epss 0.00
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
- risk 0.36cvss 5.5epss 0.00
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny service locally.
- risk 0.36cvss 5.5epss 0.00
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
- risk 0.36cvss 5.5epss 0.00
Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally.
Page 184 of 314