microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-71336 | Medium | 0.9% | 8.8 | Integer overflow or wraparound in Windows Work Folder Service allows an authoriz… | |
| CVE-2026-77888 | Medium | 0.9% | 7.5 | Access of resource using incompatible type ('type confusion') in Windows DHCP Se… | |
| CVE-2026-77889 | Medium | 0.9% | 7.5 | Access of resource using incompatible type ('type confusion') in Windows DHCP Se… | |
| CVE-2026-78456 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execut… | |
| CVE-2022-41052 | Medium | 0.8% | 7.8 | Windows Graphics Component Remote Code Execution Vulnerability | |
| CVE-2024-21384 | Medium | 0.8% | 7.8 | Microsoft Office OneNote Remote Code Execution Vulnerability | |
| CVE-2026-70563 | Medium | 0.8% | 8.1 | Improper link resolution before file access ('link following') in Windows Shell … | |
| CVE-2021-26878 | Medium | 0.8% | 7.8 | Windows Print Spooler Elevation of Privilege Vulnerability | |
| CVE-2026-45504 | Medium | 0.8% | 8.8 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an author… | |
| CVE-2026-70342 | Medium | 0.8% | 8.1 | Use after free in Windows Ancillary Function Driver for WinSock allows an unauth… | |
| CVE-2026-9135 | Medium | 0.8% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 9498… | |
| CVE-2026-50527 | Medium | 0.8% | 7.5 | Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to… | |
| CVE-2026-50648 | Medium | 0.8% | 7.5 | Allocation of resources without limits or throttling in .NET Framework allows an… | |
| CVE-2026-50651 | Medium | 0.8% | 7.5 | Allocation of resources without limits or throttling in .NET allows an unauthori… | |
| CVE-2021-26874 | Medium | 0.8% | 7.8 | Windows Overlay Filter Elevation of Privilege Vulnerability | |
| CVE-2026-50516 | Medium | 0.8% | 9.4 | Missing authentication for critical function in Microsoft Azure Kubernetes Servi… | |
| CVE-2026-33827 | Medium | 0.8% | 8.1 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62785 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protoc… | |
| CVE-2026-21267 | Medium | 0.8% | 8.6 | Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutra… | |
| CVE-2026-48295 | Medium | 0.8% | 7.5 | CAI Content Credentials is affected by an Insufficiently Protected Credentials v… | |
| CVE-2020-1078 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists in Windows Installer because of t… | |
| CVE-2020-1086 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists when the Windows Runtime improper… | |
| CVE-2020-1087 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists in the way that the Windows Kerne… | |
| CVE-2020-1090 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists when the Windows Runtime improper… | |
| CVE-2020-1124 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists when the Windows State Repository… | |
| CVE-2020-1134 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists when the Windows State Repository… | |
| CVE-2020-1144 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists when the Windows State Repository… | |
| CVE-2020-1184 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists when the Windows State Repository… | |
| CVE-2020-1185 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists when the Windows State Repository… | |
| CVE-2020-1186 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists when the Windows State Repository… | |
| CVE-2020-1187 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists when the Windows State Repository… | |
| CVE-2020-1188 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists when the Windows State Repository… | |
| CVE-2020-1189 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists when the Windows State Repository… | |
| CVE-2020-1190 | Medium | 0.8% | 7.8 | An elevation of privilege vulnerability exists when the Windows State Repository… | |
| CVE-2026-41098 | Medium | 0.8% | 8.4 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-49179 | Medium | 0.8% | 8.8 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2026-32211 | Medium | 0.8% | 9.1 | Missing authentication for critical function in Azure MCP Server allows an unaut… | |
| CVE-2022-41063 | Medium | 0.8% | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | |
| CVE-2022-41078 | Medium | 0.8% | 8.0 | Microsoft Exchange Server Spoofing Vulnerability | |
| CVE-2022-41079 | Medium | 0.8% | 8.0 | Microsoft Exchange Server Spoofing Vulnerability | |
| CVE-2026-50380 | Medium | 0.8% | 9.6 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to ex… | |
| CVE-2026-50474 | Medium | 0.8% | 8.8 | Use after free in Remote Desktop Client allows an unauthorized attacker to execu… | |
| CVE-2026-54990 | Medium | 0.8% | 9.8 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac… | |
| CVE-2026-57090 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unaut… | |
| CVE-2026-57094 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unaut… | |
| CVE-2026-58594 | Medium | 0.8% | 8.8 | Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to… | |
| CVE-2026-69442 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t… | |
| CVE-2026-69556 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attac… | |
| CVE-2026-69629 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized at… | |
| CVE-2026-69669 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to … |