microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-26890 | Medium | 0.8% | 7.8 | Application Virtualization Remote Code Execution Vulnerability | |
| CVE-2024-38183 | Medium | 0.8% | 9.8 | An improper access control vulnerability in GroupMe allows an a unauthenticated … | |
| CVE-2023-21817 | Medium | 0.8% | 7.8 | Windows Kerberos Elevation of Privilege Vulnerability | |
| CVE-2026-69724 | Medium | 0.8% | 8.8 | Missing authorization in Microsoft Office SharePoint allows an authorized attack… | |
| CVE-2026-50360 | Medium | 0.8% | 8.8 | Incorrect implementation of authentication algorithm in Windows SMB Server allow… | |
| CVE-2026-50444 | Medium | 0.8% | 8.8 | Missing authentication for critical function in Windows Server Update Service al… | |
| CVE-2026-68839 | Medium | 0.8% | 9.8 | Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an un… | |
| CVE-2026-83941 | Medium | 0.8% | 9.9 | Missing authorization in Entra ID allows an authorized attacker to elevate privi… | |
| CVE-2023-21806 | Medium | 0.8% | 8.2 | Power BI Report Server Spoofing Vulnerability | |
| CVE-2026-70587 | Medium | 0.8% | 7.5 | Improper null termination in Windows Remote Desktop Protocol allows an unauthori… | |
| CVE-2026-71330 | Medium | 0.8% | 7.5 | Exposure of sensitive system information to an unauthorized control sphere in Wi… | |
| CVE-2026-69503 | Medium | 0.8% | 8.0 | Stack-based buffer overflow in Windows USB Driver allows an authorized attacker … | |
| CVE-2026-69505 | Medium | 0.8% | 8.0 | Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate priv… | |
| CVE-2026-69875 | Medium | 0.8% | 8.0 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elev… | |
| CVE-2026-59115 | Medium | 0.8% | 9.9 | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an autho… | |
| CVE-2023-21822 | Medium | 0.8% | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability | |
| CVE-2021-26901 | Medium | 0.8% | 7.8 | Windows Event Tracing Elevation of Privilege Vulnerability | |
| CVE-2024-38243 | Medium | 0.8% | 7.8 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | |
| CVE-2023-36865 | Medium | 0.8% | 7.8 | Microsoft Office Visio Remote Code Execution Vulnerability | |
| CVE-2023-36866 | Medium | 0.8% | 7.8 | Microsoft Office Visio Remote Code Execution Vulnerability | |
| CVE-2024-38238 | Medium | 0.8% | 7.8 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | |
| CVE-2026-47281 | Medium | 0.8% | 9.6 | Missing authorization in Visual Studio Code allows an unauthorized attacker to e… | |
| CVE-2024-38119 | Medium | 0.8% | 7.5 | Windows Network Address Translation (NAT) Remote Code Execution Vulnerability | |
| CVE-2026-20848 | Medium | 0.8% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20934 | Medium | 0.8% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-56191 | Medium | 0.8% | 10.0 | Improper authentication in Microsoft Exchange Online allows an unauthorized atta… | |
| CVE-2026-47643 | Medium | 0.8% | 9.8 | External control of file name or path in Azure Stack Edge allows an unauthorized… | |
| CVE-2026-69461 | Medium | 0.8% | 8.8 | Stack-based buffer overflow in Windows NTFS allows an unauthorized attacker to e… | |
| CVE-2026-49163 | Medium | 0.8% | 8.8 | Improper limitation of a pathname to a restricted directory ('path traversal') i… | |
| CVE-2026-77482 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in SQL Server allows an unauthorized attacker to exec… | |
| CVE-2026-77906 | Medium | 0.8% | 8.8 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to e… | |
| CVE-2026-70306 | Medium | 0.7% | 9.3 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-7755 | Medium | 0.7% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution… | |
| CVE-2026-50340 | Medium | 0.7% | 8.5 | Use after free in Windows Runtime allows an authorized attacker to elevate privi… | |
| CVE-2026-50500 | Medium | 0.7% | 7.5 | Use after free in Windows Netlogon allows an authorized attacker to elevate priv… | |
| CVE-2026-50505 | Medium | 0.7% | 7.5 | Use after free in Windows Message Queuing allows an authorized attacker to execu… | |
| CVE-2023-21718 | Medium | 0.7% | 7.8 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | |
| CVE-2023-21805 | Medium | 0.7% | 7.8 | Windows MSHTML Platform Remote Code Execution Vulnerability | |
| CVE-2026-47303 | Medium | 0.7% | 8.8 | Authentication bypass by assumed-immutable data in ASP.NET Core allows an author… | |
| CVE-2026-62835 | Medium | 0.7% | 9.3 | Improper authorization in Azure Portal allows an unauthorized attacker to disclo… | |
| CVE-2026-62827 | Medium | 0.7% | 8.8 | Improper authentication in Microsoft Office SharePoint allows an authorized atta… | |
| CVE-2026-66819 | Medium | 0.7% | 8.8 | Improper neutralization of special elements used in an sql command ('sql injecti… | |
| CVE-2026-69268 | Medium | 0.7% | 8.8 | Improper access control in Microsoft Office SharePoint allows an authorized atta… | |
| CVE-2026-80096 | Medium | 0.7% | 8.8 | Out-of-bounds read in Windows Remote Desktop Services allows an authorized attac… | |
| CVE-2022-41092 | Medium | 0.7% | 7.8 | Windows Win32k Elevation of Privilege Vulnerability | |
| CVE-2026-9103 | Medium | 0.7% | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unau… | |
| CVE-2026-48347 | Medium | 0.7% | 7.7 | Animate is affected by an Improper Neutralization of Special Elements used in an… | |
| CVE-2026-56165 | Medium | 0.7% | 9.8 | Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker … | |
| CVE-2026-33105 | Medium | 0.7% | 10.0 | Improper authorization in Microsoft Azure Kubernetes Service allows an unauthori… | |
| CVE-2023-36898 | Medium | 0.7% | 7.8 | Tablet Windows User Interface Application Core Remote Code Execution Vulnerabili… |