microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-69671 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attac… | |
| CVE-2026-69686 | Medium | 0.8% | 8.8 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized atta… | |
| CVE-2026-69722 | Medium | 0.8% | 8.8 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized atta… | |
| CVE-2026-69742 | Medium | 0.8% | 8.8 | Integer overflow or wraparound in Microsoft Office Publisher allows an unauthori… | |
| CVE-2026-69759 | Medium | 0.8% | 8.8 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized atta… | |
| CVE-2026-69764 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attac… | |
| CVE-2026-69778 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized att… | |
| CVE-2026-72972 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attac… | |
| CVE-2026-72973 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attac… | |
| CVE-2026-78511 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attac… | |
| CVE-2026-78512 | Medium | 0.8% | 8.8 | Numeric truncation error in Microsoft Office Word allows an unauthorized attacke… | |
| CVE-2026-78524 | Medium | 0.8% | 8.8 | Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execu… | |
| CVE-2022-41119 | Medium | 0.8% | 7.8 | Visual Studio Remote Code Execution Vulnerability | |
| CVE-2026-69465 | Medium | 0.8% | 8.8 | Missing authorization in Microsoft Office SharePoint allows an authorized attack… | |
| CVE-2026-77501 | Medium | 0.8% | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to den… | |
| CVE-2026-62869 | Medium | 0.8% | 8.8 | Insufficient verification of data authenticity in Azure Entra ID allows an autho… | |
| CVE-2026-67376 | Medium | 0.8% | 7.5 | Integer overflow or wraparound in SQL Server allows an unauthorized attacker to … | |
| CVE-2026-68887 | Medium | 0.8% | 7.5 | Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthoriz… | |
| CVE-2026-77498 | Medium | 0.8% | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to den… | |
| CVE-2026-77502 | Medium | 0.8% | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to den… | |
| CVE-2026-77886 | Medium | 0.8% | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to den… | |
| CVE-2026-77893 | Medium | 0.8% | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to den… | |
| CVE-2021-33751 | Medium | 0.8% | 7.0 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | |
| CVE-2026-20919 | Medium | 0.8% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20926 | Medium | 0.8% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-57104 | Medium | 0.8% | 8.8 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-58612 | Medium | 0.8% | 7.4 | Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauth… | |
| CVE-2026-65660 | Medium | 0.8% | 8.8 | Improper control of generation of code ('code injection') in Microsoft Office Sh… | |
| CVE-2026-8481 | Medium | 0.8% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution v… | |
| CVE-2021-24095 | Medium | 0.8% | 7.0 | DirectX Elevation of Privilege Vulnerability | |
| CVE-2026-69518 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized atta… | |
| CVE-2026-70203 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Windows Media Player allows an unauthorized attack… | |
| CVE-2026-69632 | Medium | 0.8% | 8.8 | Use after free in Microsoft Office allows an unauthorized attacker to execute co… | |
| CVE-2026-69678 | Medium | 0.8% | 8.8 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to… | |
| CVE-2026-69767 | Medium | 0.8% | 8.8 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to… | |
| CVE-2026-69797 | Medium | 0.8% | 8.8 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to… | |
| CVE-2026-69860 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Windows Imaging Component allows an unauthorized a… | |
| CVE-2026-70586 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to e… | |
| CVE-2026-73006 | Medium | 0.8% | 8.8 | Stack-based buffer overflow in Microsoft Graphics Component allows an unauthoriz… | |
| CVE-2026-78505 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t… | |
| CVE-2026-78525 | Medium | 0.8% | 8.8 | Use after free in Microsoft Office Outlook allows an unauthorized attacker to ex… | |
| CVE-2024-21363 | Medium | 0.8% | 7.8 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | |
| CVE-2024-43465 | Medium | 0.8% | 7.8 | Microsoft Excel Elevation of Privilege Vulnerability | |
| CVE-2022-41051 | Medium | 0.8% | 7.8 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| CVE-2026-70337 | Medium | 0.8% | 8.8 | Relative path traversal in Microsoft PowerShell Core allows an unauthorized atta… | |
| CVE-2026-49164 | Medium | 0.8% | 8.1 | Heap-based buffer overflow in Active Directory Domain Services allows an unautho… | |
| CVE-2026-50439 | Medium | 0.8% | 8.1 | Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized… | |
| CVE-2026-50487 | Medium | 0.8% | 8.1 | Use after free in Microsoft Windows DNS allows an unauthorized attacker to eleva… | |
| CVE-2026-50694 | Medium | 0.8% | 8.1 | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unau… | |
| CVE-2026-57087 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unaut… |