microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-10975 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-10982 | Medium | 0.5% | 8.8 | Use after free in WebXR in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-11003 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-69320 | Medium | 0.5% | 8.8 | Improper neutralization of special elements used in an os command ('os command i… | |
| CVE-2026-8855 | Medium | 0.5% | 8.1 | IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o… | |
| CVE-2026-44819 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t… | |
| CVE-2026-44824 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t… | |
| CVE-2026-45471 | Medium | 0.5% | 7.8 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized at… | |
| CVE-2026-45475 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t… | |
| CVE-2026-65767 | Medium | 0.5% | 8.8 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-71331 | Medium | 0.5% | 8.1 | Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows… | |
| CVE-2026-45497 | Medium | 0.5% | 7.7 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2026-62918 | Medium | 0.5% | 7.5 | Improper verification of cryptographic signature in Microsoft Teams allows an un… | |
| CVE-2026-47938 | Medium | 0.4% | 10.0 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected … | |
| CVE-2026-81388 | Medium | 0.4% | 7.8 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized att… | |
| CVE-2026-64900 | Medium | 0.4% | 7.3 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-69417 | Medium | 0.4% | 7.3 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2023-23379 | Medium | 0.4% | 7.8 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | |
| CVE-2026-45503 | Medium | 0.4% | 8.1 | Improper authorization in Microsoft Exchange Server allows an authorized attacke… | |
| CVE-2026-48574 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to e… | |
| CVE-2026-65807 | Medium | 0.4% | 8.8 | Access of resource using incompatible type ('type confusion') in Microsoft Offic… | |
| CVE-2026-69555 | Medium | 0.4% | 10.0 | Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate … | |
| CVE-2026-78978 | Medium | 0.4% | 8.8 | Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.6… | |
| CVE-2026-47292 | Medium | 0.4% | 7.8 | Inclusion of functionality from untrusted control sphere in Visual Studio Code a… | |
| CVE-2026-65657 | Medium | 0.4% | 7.8 | Use after free in Microsoft Office allows an unauthorized attacker to execute co… | |
| CVE-2026-69536 | Medium | 0.4% | 7.1 | Use after free in Windows Remote Desktop Services allows an authorized attacker … | |
| CVE-2026-42904 | Medium | 0.4% | 9.6 | Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to … | |
| CVE-2026-45456 | Medium | 0.4% | 8.4 | Access of resource using incompatible type ('type confusion') in Microsoft Offic… | |
| CVE-2026-45458 | Medium | 0.4% | 8.4 | Use after free in Microsoft Office allows an unauthorized attacker to execute co… | |
| CVE-2023-23381 | Medium | 0.4% | 7.8 | Visual Studio Remote Code Execution Vulnerability | |
| CVE-2026-69857 | Medium | 0.4% | 8.5 | Authorization bypass through user-controlled key in Azure Cosmos DB allows an au… | |
| CVE-2026-50347 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker t… | |
| CVE-2026-62836 | Medium | 0.4% | 8.7 | Improper restriction of communication channel to intended endpoints in Azure SQL… | |
| CVE-2026-70334 | Medium | 0.4% | 7.8 | Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorize… | |
| CVE-2026-19158 | Medium | 0.4% | 7.5 | Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allo… | |
| CVE-2026-42993 | Medium | 0.4% | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac… | |
| CVE-2026-72984 | Medium | 0.4% | 8.8 | Access of resource using incompatible type ('type confusion') in Microsoft Edge … | |
| CVE-2026-48565 | Medium | 0.4% | 7.8 | Untrusted search path in Windows Narrator Braille allows an authorized attacker … | |
| CVE-2026-69266 | Medium | 0.4% | 8.8 | Integer overflow or wraparound in Windows DHCP Server allows an unauthorized att… | |
| CVE-2026-85877 | Medium | 0.4% | 8.8 | Heap-based buffer overflow in Windows Print Spooler Components allows an unautho… | |
| CVE-2026-34711 | Medium | 0.4% | 7.5 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are af… | |
| CVE-2026-45649 | Medium | 0.4% | 7.1 | Improper access control in Office for Android allows an unauthorized attacker to… | |
| CVE-2026-61352 | Medium | 0.4% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-70178 | Medium | 0.4% | 8.5 | Missing authorization in Microsoft Fabric allows an authorized attacker to eleva… | |
| CVE-2026-35430 | Medium | 0.4% | 8.8 | Authorization bypass through user-controlled key in Azure Privileged Identity Ma… | |
| CVE-2026-69851 | Medium | 0.4% | 9.9 | Server-side request forgery (ssrf) in Azure Active Directory allows an authorize… | |
| CVE-2026-81948 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… | |
| CVE-2026-81949 | Medium | 0.4% | 7.8 | Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized … | |
| CVE-2026-81950 | Medium | 0.4% | 7.8 | Double free in Microsoft Office Excel allows an unauthorized attacker to execute… | |
| CVE-2026-81951 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… |