Vendor CVEs
Microsoft
All CVEs
15,666 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-32215 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2026-32214 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. | ||
| CVE-2026-32212 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. | ||
| CVE-2026-32181 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally. | ||
| CVE-2026-32085 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally. | ||
| CVE-2026-32084 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-32081 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-32079 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-27931 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-27930 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-20806 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally. | ||
| CVE-2026-26123 | Med | 0.36 | 5.5 | 0.01 | Mar 10, 2026 | Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-25186 | Med | 0.36 | 5.5 | 0.01 | Mar 10, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to disclose information locally. | ||
| CVE-2026-25180 | Med | 0.36 | 5.5 | 0.01 | Mar 10, 2026 | Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-24282 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2026 | Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. | ||
| CVE-2026-2636 | Med | 0.36 | 5.5 | 0.00 | Feb 25, 2026 | This vulnerability is caused by a CWE‑159: "Improper Handling of Invalid Use of Special Elements" weakness, which leads to an unrecoverable inconsistency in the CLFS.sys driver. This condition forces a call to the KeBugCheckEx function, allowing an unprivileged user to trigger… | ||
| CVE-2026-21261 | Med | 0.36 | 5.5 | 0.01 | Feb 10, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-21258 | Med | 0.36 | 5.5 | 0.01 | Feb 10, 2026 | Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-21222 | Med | 0.36 | 5.5 | 0.01 | Feb 10, 2026 | Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20939 | Med | 0.36 | 5.5 | 0.00 | Jan 13, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20937 | Med | 0.36 | 5.5 | 0.00 | Jan 13, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20932 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20862 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20839 | Med | 0.36 | 5.5 | 0.00 | Jan 13, 2026 | Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20838 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20835 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20833 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20829 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20827 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20824 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally. | ||
| CVE-2026-20823 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20819 | Med | 0.36 | 5.5 | 0.01 | Jan 13, 2026 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. | ||
| CVE-2025-62224 | Med | 0.36 | 5.5 | 0.00 | Jan 7, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2025-62468 | Med | 0.36 | 5.5 | 0.01 | Dec 9, 2025 | Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally. | ||
| CVE-2025-62209 | Med | 0.36 | 5.5 | 0.01 | Nov 11, 2025 | Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally. | ||
| CVE-2025-62208 | Med | 0.36 | 5.5 | 0.01 | Nov 11, 2025 | Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally. | ||
| CVE-2025-60706 | Med | 0.36 | 5.5 | 0.00 | Nov 11, 2025 | Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59513 | Med | 0.36 | 5.5 | 0.00 | Nov 11, 2025 | Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59510 | Med | 0.36 | 5.5 | 0.01 | Nov 11, 2025 | Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally. | ||
| CVE-2025-59509 | Med | 0.36 | 5.5 | 0.01 | Nov 11, 2025 | Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59240 | Med | 0.36 | 5.5 | 0.01 | Nov 11, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | ||
| CVE-2025-59260 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59253 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally. | ||
| CVE-2025-59229 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally. | ||
| CVE-2025-59211 | Med | 0.36 | 5.5 | 0.01 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59209 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59204 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59203 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59197 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally. | ||
| CVE-2025-59190 | Med | 0.36 | 5.5 | 0.00 | Oct 14, 2025 | Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally. |
- risk 0.36cvss 5.5epss 0.00
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
This vulnerability is caused by a CWE‑159: "Improper Handling of Invalid Use of Special Elements" weakness, which leads to an unrecoverable inconsistency in the CLFS.sys driver. This condition forces a call to the KeBugCheckEx function, allowing an unprivileged user to trigger…
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network.
- risk 0.36cvss 5.5epss 0.01
Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally.
- risk 0.36cvss 5.5epss 0.01
Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
- risk 0.36cvss 5.5epss 0.00
Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally.
- risk 0.36cvss 5.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Use of uninitialized resource in Windows Management Services allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.
Page 185 of 314