microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-38652 | Medium | 1.3% | 7.6 | Microsoft SharePoint Server Spoofing Vulnerability | |
| CVE-2026-62911 | Medium | 1.3% | 8.0 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an a… | |
| CVE-2023-38169 | Medium | 1.3% | 8.8 | Microsoft SQL OLE DB Remote Code Execution Vulnerability | |
| CVE-2024-21328 | Medium | 1.3% | 7.6 | Dynamics 365 Sales Spoofing Vulnerability | |
| CVE-2021-36975 | Medium | 1.3% | 7.8 | Win32k Elevation of Privilege Vulnerability | |
| CVE-2023-38186 | Medium | 1.3% | 8.8 | Windows Mobile Device Management Elevation of Privilege Vulnerability | |
| CVE-2021-34516 | Medium | 1.3% | 7.8 | Win32k Elevation of Privilege Vulnerability | |
| CVE-2023-21684 | Medium | 1.3% | 8.8 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnera… | |
| CVE-2024-21327 | Medium | 1.3% | 7.6 | Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability | |
| CVE-2026-70321 | Medium | 1.3% | 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an autho… | |
| CVE-2024-38194 | Medium | 1.3% | 8.4 | An authenticated attacker can exploit an improper authorization vulnerability in… | |
| CVE-2026-20803 | Medium | 1.3% | 7.2 | Missing authentication for critical function in SQL Server allows an authorized … | |
| CVE-2024-43474 | Medium | 1.3% | 7.6 | Microsoft SQL Server Information Disclosure Vulnerability | |
| CVE-2026-42985 | Medium | 1.3% | 8.8 | Use after free in Remote Desktop Client allows an unauthorized attacker to execu… | |
| CVE-2026-62878 | Medium | 1.3% | 9.8 | Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to ex… | |
| CVE-2026-42835 | Medium | 1.3% | 8.1 | Improper neutralization of special elements in output used by a downstream compo… | |
| CVE-2026-50517 | Medium | 1.3% | 9.9 | Deserialization of untrusted data in M365 Copilot allows an authorized attacker … | |
| CVE-2026-50330 | Medium | 1.3% | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac… | |
| CVE-2026-33096 | Medium | 1.2% | 7.5 | Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny s… | |
| CVE-2026-62815 | Medium | 1.2% | 9.8 | Use after free in Microsoft QUIC allows an unauthorized attacker to execute code… | |
| CVE-2021-33768 | Medium | 1.2% | 8.0 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| CVE-2024-21399 | Medium | 1.2% | 8.3 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| CVE-2022-41061 | Medium | 1.2% | 7.8 | Microsoft Word Remote Code Execution Vulnerability | |
| CVE-2023-21685 | Medium | 1.2% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2026-69587 | Medium | 1.2% | 7.5 | Null pointer dereference in Windows IKE Extension allows an unauthorized attacke… | |
| CVE-2026-69588 | Medium | 1.2% | 7.5 | Missing release of memory after effective lifetime in Windows TCP/IP allows an u… | |
| CVE-2026-32225 | Medium | 1.2% | 8.8 | Protection mechanism failure in Windows Shell allows an unauthorized attacker to… | |
| CVE-2026-20921 | Medium | 1.2% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2023-21797 | Medium | 1.2% | 8.8 | Microsoft ODBC Driver Remote Code Execution Vulnerability | |
| CVE-2023-21798 | Medium | 1.2% | 8.8 | Microsoft ODBC Driver Remote Code Execution Vulnerability | |
| CVE-2023-21799 | Medium | 1.2% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2024-20673 | Medium | 1.2% | 7.8 | Microsoft Office Remote Code Execution Vulnerability | |
| CVE-2026-69881 | Medium | 1.2% | 7.5 | Null pointer dereference in Windows IKE Extension allows an unauthorized attacke… | |
| CVE-2026-40378 | Medium | 1.2% | 7.5 | Memory allocation with excessive size value in Windows Local Security Authority … | |
| CVE-2026-49787 | Medium | 1.2% | 7.5 | Allocation of resources without limits or throttling in Windows HTTP.sys allows … | |
| CVE-2026-49788 | Medium | 1.2% | 7.5 | Allocation of resources without limits or throttling in HTTP/2 allows an unautho… | |
| CVE-2026-50304 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services allows an un… | |
| CVE-2026-50355 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services allows an un… | |
| CVE-2026-50368 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services allows an un… | |
| CVE-2026-50411 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services (AD FS) allo… | |
| CVE-2026-50424 | Medium | 1.2% | 7.5 | Untrusted pointer dereference in Windows Domain Controller allows an unauthorize… | |
| CVE-2026-50496 | Medium | 1.2% | 7.5 | Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized … | |
| CVE-2026-50506 | Medium | 1.2% | 7.5 | Allocation of resources without limits or throttling in ASP.NET Core allows an u… | |
| CVE-2026-50647 | Medium | 1.2% | 7.5 | Loop with unreachable exit condition ('infinite loop') in Active Directory Feder… | |
| CVE-2026-50653 | Medium | 1.2% | 7.5 | Loop with unreachable exit condition ('infinite loop') in Azure Active Directory… | |
| CVE-2026-50695 | Medium | 1.2% | 7.5 | Stack-based buffer overflow in Active Directory Federation Services allows an un… | |
| CVE-2026-50696 | Medium | 1.2% | 7.5 | Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allow… | |
| CVE-2026-54119 | Medium | 1.2% | 7.5 | Loop with unreachable exit condition ('infinite loop') in Windows Active Directo… | |
| CVE-2026-70065 | Medium | 1.2% | 7.5 | Missing release of memory after effective lifetime in Windows DHCP Server allows… | |
| CVE-2026-77494 | Medium | 1.2% | 7.5 | Access of resource using incompatible type ('type confusion') in Windows DHCP Se… |