Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2026-69414
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "Shield…
Malware Protection Engine
No fix yet
HIGH 7.8
CVE-2026-68821
Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
App Installer
1.30.80+
HIGH 7.8
CVE-2026-50391
Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.8
CVE-2026-50343
Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.9020 / 10.0.19044.7548+
MEDIUM 5.5
CVE-2026-50295
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.
Windows 11 24h2
10.0.26100.8875 / 10.0.26100.33158+
HIGH 7.8
CVE-2026-49176
Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.5
CVE-2026-23663
Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.
Global Secure Access
No fix yet
CRITICAL 9.9
CVE-2026-33821
Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.
Dynamics 365 Customer Insights
Mitigation only
MEDIUM 5.5
CVE-2026-32212
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose inform…
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
MEDIUM 5.5
CVE-2026-32181
Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.
Windows 10 21h2
10.0.19044.7184 / 10.0.19045.7184+
HIGH 7.8
CVE-2026-21533 KEV
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.1
CVE-2026-21223
Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
Edge Chromium
144.0.3719.82+
HIGH 7.8
CVE-2025-59514
Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
CRITICAL 9.8
CVE-2025-59247
Azure PlayFab Elevation of Privilege Vulnerability
Azure Playfab
No fix yet
HIGH 8.8
CVE-2025-49758
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…
Sql Server 2016
13.0.6465.1 / 13.0.7060.1+
HIGH 7.8
CVE-2025-47955
Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
HIGH 8.4
CVE-2025-33067
Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21034 / 10.0.14393.8148+
HIGH 7.8
CVE-2025-29976
Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally.
Sharepoint Server
16.0.18526.20286+
HIGH 7.0
CVE-2025-27468
Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
HIGH 7.8
CVE-2025-29800
Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
Autoupdate
4.78+
MEDIUM 6.7
CVE-2025-21199
Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.
Azure Agent
2.0.9940.0 / 9.30+
HIGH 7.8
CVE-2025-21360
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
Autoupdate
4.76+
HIGH 7.5
CVE-2025-21343
Windows Web Threat Defense User Service Information Disclosure Vulnerability
Windows 11 22h2
10.0.22621.4751 / 10.0.22631.4751+
HIGH 7.8
CVE-2025-21287
Windows Installer Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20890 / 10.0.14393.7699+
CRITICAL 9.8
CVE-2024-49035 KEV
An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.
Partner Center
Mitigation only
HIGH 7.8
CVE-2024-38014 KEVEPSS 6%
Windows Installer Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20766 / 10.0.14393.7336+
CRITICAL 9.8
CVE-2024-37980
Microsoft SQL Server Elevation of Privilege Vulnerability
Sql Server 2016
13.0.6445.1 / 13.0.7040.1+
CRITICAL 9.9
CVE-2024-38089
Microsoft Defender for IoT Elevation of Privilege Vulnerability
Defender For Iot
24.1.4+
HIGH 8.8
CVE-2024-30007
Microsoft Brokering File System Elevation of Privilege Vulnerability
Windows Server 2022 23h2
10.0.25398.887+
HIGH 7.8
CVE-2024-29052
Windows Storage Elevation of Privilege Vulnerability
Windows 10 21h2
10.0.19044.4291 / 10.0.19045.4291+