microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2015-1701 | Act now | 56.2% | 7.8 | ● | Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vist… |
| CVE-2024-43461 | Act now | 54.5% | 8.8 | ● | Windows MSHTML Platform Spoofing Vulnerability |
| CVE-2020-1054 | Act now | 54.2% | 7.0 | ● | An elevation of privilege vulnerability exists in Windows when the Windows kerne… |
| CVE-2021-31196 | Act now | 54.1% | 7.2 | ● | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2019-1068 | Act now | 52.8% | 8.8 | ● | A remote code execution vulnerability exists in Microsoft SQL Server when it inc… |
| CVE-2021-20023 | Act now | 51.4% | 4.9 | ● | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a… |
| CVE-2026-55040 | Act now | 50.6% | 9.1 | ● | Weak authentication in Microsoft Office SharePoint allows an unauthorized attack… |
| CVE-2021-42292 | Act now | 43.0% | 7.8 | ● | Microsoft Excel Security Feature Bypass Vulnerability |
| CVE-2020-0787 | Act now | 42.5% | 7.8 | ● | An elevation of privilege vulnerability exists when the Windows Background Intel… |
| CVE-2021-34448 | Act now | 40.1% | 6.8 | ● | Scripting Engine Memory Corruption Vulnerability |
| CVE-2025-26633 | Act now | 30.4% | 7.0 | ● | Improper neutralization in Microsoft Management Console allows an unauthorized a… |
| CVE-2024-21351 | Act now | 30.3% | 7.6 | ● | Windows SmartScreen Security Feature Bypass Vulnerability |
| CVE-2019-1405 | Act now | 30.0% | 7.8 | ● | An elevation of privilege vulnerability exists when the Windows Universal Plug a… |
| CVE-2022-37969 | Act now | 28.3% | 7.8 | ● | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2016-3351 | Act now | 26.3% | 6.5 | ● | Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attacke… |
| CVE-2022-41128 | Act now | 24.6% | 8.8 | ● | Windows Scripting Languages Remote Code Execution Vulnerability |
| CVE-2021-36948 | Act now | 23.3% | 7.8 | ● | Windows Update Medic Service Elevation of Privilege Vulnerability |
| CVE-2016-1019 | Act now | 22.3% | 9.8 | ● | Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a den… |
| CVE-2021-34484 | Act now | 21.8% | 7.8 | ● | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2021-41379 | Act now | 19.5% | 5.5 | ● | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2021-20022 | Act now | 16.5% | 7.2 | ● | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a… |
| CVE-2024-49039 | Act now | 14.2% | 8.8 | ● | Windows Task Scheduler Elevation of Privilege Vulnerability |
| CVE-2023-38180 | Act now | 14.0% | 7.5 | ● | .NET and Visual Studio Denial of Service Vulnerability |
| CVE-2023-21715 | Act now | 12.0% | 7.3 | ● | Microsoft Publisher Security Feature Bypass Vulnerability |
| CVE-2021-38648 | Act now | 11.4% | 7.8 | ● | Open Management Infrastructure Elevation of Privilege Vulnerability |
| CVE-2023-23376 | Act now | 10.9% | 7.8 | ● | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2021-43890 | Act now | 10.3% | 7.1 | ● | We have investigated reports of a spoofing vulnerability in AppX installer that … |
| CVE-2021-33771 | Act now | 10.2% | 7.8 | ● | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2015-2546 | Act now | 10.1% | 8.2 | ● | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 a… |
| CVE-2024-38217 | Act now | 10.0% | 5.4 | ● | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2021-34486 | Act now | 9.3% | 7.8 | ● | Windows Event Tracing Elevation of Privilege Vulnerability |
| CVE-2015-2291 | Act now | 9.0% | 7.8 | ● | (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Eth… |
| CVE-2026-41091 | Act now | 8.2% | 7.8 | ● | Improper link resolution before file access ('link following') in Microsoft Defe… |
| CVE-2021-38646 | Act now | 8.0% | 7.8 | ● | Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability |
| CVE-2026-34621 | Act now | 7.1% | 8.6 | ● | Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by a… |
| CVE-2026-33825 | Act now | 6.7% | 7.8 | ● | Insufficient granularity of access control in Microsoft Defender allows an autho… |
| CVE-2024-38014 | Act now | 6.3% | 7.8 | ● | Windows Installer Elevation of Privilege Vulnerability |
| CVE-2026-68820 | Act now | 6.2% | 7.0 | ● | Use after free in Windows Ancillary Function Driver for WinSock allows an author… |
| CVE-2019-1069 | Act now | 6.1% | 7.8 | ● | An elevation of privilege vulnerability exists in the way the Task Scheduler Ser… |
| CVE-2021-27059 | Act now | 6.1% | 7.6 | ● | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2023-21823 | Act now | 5.6% | 7.8 | ● | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2021-27085 | Act now | 5.4% | 8.8 | ● | Internet Explorer Remote Code Execution Vulnerability |
| CVE-2026-20805 | Act now | 5.2% | 5.5 | ● | Exposure of sensitive information to an unauthorized actor in Desktop Windows Ma… |
| CVE-2026-5281 | Act now | 4.9% | 8.8 | ● | Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote… |
| CVE-2021-31979 | Act now | 4.5% | 7.8 | ● | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2021-36955 | Act now | 4.0% | 7.8 | ● | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2019-1385 | Act now | 3.6% | 7.8 | ● | An elevation of privilege vulnerability exists when the Windows AppX Deployment … |
| CVE-2021-43226 | Act now | 3.1% | 7.8 | ● | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2020-0638 | Act now | 3.0% | 7.8 | ● | An elevation of privilege vulnerability exists in the way the Update Notificatio… |
| CVE-2022-41125 | Act now | 3.0% | 7.8 | ● | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability |