microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-56642 | Medium | 0.9% | 8.8 | Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authori… | |
| CVE-2026-56647 | Medium | 0.9% | 8.8 | Integer overflow or wraparound in Windows Remote Access Service Infrastructure a… | |
| CVE-2026-57092 | Medium | 0.9% | 9.9 | Use after free in Windows VMSwitch allows an authorized attacker to elevate priv… | |
| CVE-2026-58626 | Medium | 0.9% | 8.8 | Use after free in Windows Remote Desktop Services allows an authorized attacker … | |
| CVE-2021-36967 | Medium | 0.9% | 8.0 | Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability | |
| CVE-2026-32173 | Medium | 0.9% | 8.6 | Improper authentication in Azure SRE Agent allows an unauthorized attacker to di… | |
| CVE-2026-69463 | Medium | 0.9% | 9.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2021-33767 | Medium | 0.9% | 8.2 | Open Enclave SDK Elevation of Privilege Vulnerability | |
| CVE-2021-1640 | Medium | 0.9% | 7.8 | Windows Print Spooler Elevation of Privilege Vulnerability | |
| CVE-2026-73025 | Medium | 0.9% | 9.8 | Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a… | |
| CVE-2024-30073 | Medium | 0.9% | 7.8 | Windows Security Zone Mapping Security Feature Bypass Vulnerability | |
| CVE-2021-26425 | Medium | 0.9% | 7.8 | Windows Event Tracing Elevation of Privilege Vulnerability | |
| CVE-2026-69491 | Medium | 0.9% | 9.8 | Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthoriz… | |
| CVE-2026-48345 | Medium | 0.9% | 8.2 | Animate is affected by an Improper Neutralization of Special Elements used in an… | |
| CVE-2026-78445 | Medium | 0.9% | 9.8 | Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthori… | |
| CVE-2024-43476 | Medium | 0.9% | 7.6 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| CVE-2026-67643 | Medium | 0.9% | 9.8 | Heap-based buffer overflow in SQL Server allows an unauthorized attacker to exec… | |
| CVE-2026-73009 | Medium | 0.9% | 9.8 | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unau… | |
| CVE-2026-73010 | Medium | 0.9% | 9.8 | Use after free in Windows Failover Cluster allows an unauthorized attacker to ex… | |
| CVE-2023-21564 | Medium | 0.9% | 7.1 | Azure DevOps Server Cross-Site Scripting Vulnerability | |
| CVE-2026-65681 | Medium | 0.9% | 7.5 | Null pointer dereference in Windows iSCSI Target Service allows an unauthorized … | |
| CVE-2021-26434 | Medium | 0.9% | 7.8 | Visual Studio Elevation of Privilege Vulnerability | |
| CVE-2024-43479 | Medium | 0.9% | 8.5 | Microsoft Power Automate Desktop Remote Code Execution Vulnerability | |
| CVE-2024-38245 | Medium | 0.9% | 7.8 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | |
| CVE-2021-26898 | Medium | 0.9% | 7.8 | Windows Event Tracing Elevation of Privilege Vulnerability | |
| CVE-2026-42908 | Medium | 0.9% | 7.5 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose in… | |
| CVE-2026-45639 | Medium | 0.9% | 7.5 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose in… | |
| CVE-2020-1088 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists in Windows Error Reporting (WER) … | |
| CVE-2026-83989 | Medium | 0.9% | 7.5 | Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unaut… | |
| CVE-2026-40400 | Medium | 0.9% | 8.0 | Relative path traversal in Windows PowerShell allows an authorized attacker to e… | |
| CVE-2021-38634 | Medium | 0.9% | 7.1 | Microsoft Windows Update Client Elevation of Privilege Vulnerability | |
| CVE-2026-48561 | Medium | 0.9% | 9.6 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2026-55008 | Medium | 0.9% | 9.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-41109 | Medium | 0.9% | 8.8 | Improper neutralization of special elements in output used by a downstream compo… | |
| CVE-2026-69614 | Medium | 0.9% | 8.8 | Stack-based buffer overflow in Microsoft Office Access allows an unauthorized at… | |
| CVE-2026-78518 | Medium | 0.9% | 8.8 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2021-26875 | Medium | 0.9% | 7.8 | Windows Win32k Elevation of Privilege Vulnerability | |
| CVE-2021-26891 | Medium | 0.9% | 7.8 | Windows Container Execution Agent Elevation of Privilege Vulnerability | |
| CVE-2020-1077 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when the Windows Runtime improper… | |
| CVE-2026-20931 | Medium | 0.9% | 8.0 | External control of file name or path in Windows Telephony Service allows an aut… | |
| CVE-2022-41107 | Medium | 0.9% | 7.8 | Microsoft Office Graphics Remote Code Execution Vulnerability | |
| CVE-2024-21406 | Medium | 0.9% | 7.5 | Windows Printing Service Spoofing Vulnerability | |
| CVE-2020-1121 | Medium | 0.9% | 7.0 | An elevation of privilege vulnerability exists when Windows improperly handles c… | |
| CVE-2020-1132 | Medium | 0.9% | 7.0 | An elevation of privilege vulnerability exists when Windows Error Reporting mana… | |
| CVE-2020-1138 | Medium | 0.9% | 7.0 | An elevation of privilege vulnerability exists when the Storage Service improper… | |
| CVE-2024-43470 | Medium | 0.9% | 7.3 | Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | |
| CVE-2026-77499 | Medium | 0.9% | 7.5 | Access of resource using incompatible type ('type confusion') in Windows DHCP Se… | |
| CVE-2026-77890 | Medium | 0.9% | 7.5 | Access of resource using incompatible type ('type confusion') in Windows DHCP Se… | |
| CVE-2021-34462 | Medium | 0.9% | 7.0 | Windows AppX Deployment Extensions Elevation of Privilege Vulnerability | |
| CVE-2026-45584 | Medium | 0.9% | 8.1 | Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker… |