microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-10917 | Medium | 0.3% | 8.3 | Insufficient validation of untrusted input in Media in Google Chrome prior to 14… | |
| CVE-2026-20826 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20831 | Medium | 0.3% | 7.8 | Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function … | |
| CVE-2026-54127 | Medium | 0.3% | 7.4 | Use after free in Windows Hyper-V allows an unauthorized attacker to elevate pri… | |
| CVE-2026-14973 | Medium | 0.3% | 9.3 | IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow fil… | |
| CVE-2026-27243 | Medium | 0.3% | 9.3 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cro… | |
| CVE-2026-27245 | Medium | 0.3% | 9.3 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cro… | |
| CVE-2026-27246 | Medium | 0.3% | 9.3 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cro… | |
| CVE-2026-81994 | Medium | 0.3% | 8.2 | Acrobat Reader is affected by an Improperly Controlled Modification of Object Pr… | |
| CVE-2026-83498 | Medium | 0.3% | 7.8 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enc… | |
| CVE-2026-10922 | Medium | 0.3% | 8.8 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to… | |
| CVE-2026-45588 | Medium | 0.3% | 7.9 | Protection mechanism failure in Windows Secure Boot allows an authorized attacke… | |
| CVE-2026-47656 | Medium | 0.3% | 7.9 | Protection mechanism failure in Windows Boot Manager allows an authorized attack… | |
| CVE-2026-48568 | Medium | 0.3% | 7.9 | Protection mechanism failure in Windows Secure Boot allows an authorized attacke… | |
| CVE-2026-48570 | Medium | 0.3% | 7.9 | Protection mechanism failure in Windows Secure Boot allows an authorized attacke… | |
| CVE-2026-48575 | Medium | 0.3% | 7.9 | Protection mechanism failure in Windows Secure Boot allows an authorized attacke… | |
| CVE-2026-50459 | Medium | 0.3% | 7.0 | Use after free in Windows Kernel allows an unauthorized attacker to elevate priv… | |
| CVE-2026-5861 | Medium | 0.3% | 8.8 | Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote at… | |
| CVE-2026-5862 | Medium | 0.3% | 8.8 | Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allow… | |
| CVE-2026-5866 | Medium | 0.3% | 8.8 | Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote… | |
| CVE-2026-5872 | Medium | 0.3% | 8.8 | Use after free in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote… | |
| CVE-2026-5877 | Medium | 0.3% | 8.8 | Use after free in Navigation in Google Chrome prior to 147.0.7727.55 allowed a r… | |
| CVE-2026-63527 | Medium | 0.3% | 7.8 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized atta… | |
| CVE-2026-63533 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t… | |
| CVE-2026-64904 | Medium | 0.3% | 7.8 | Access of resource using incompatible type ('type confusion') in Microsoft Offic… | |
| CVE-2026-64905 | Medium | 0.3% | 7.8 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to exe… | |
| CVE-2026-64906 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized att… | |
| CVE-2026-64908 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized att… | |
| CVE-2026-64912 | Medium | 0.3% | 7.8 | Stack-based buffer overflow in Microsoft Office Access allows an unauthorized at… | |
| CVE-2026-64915 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attac… | |
| CVE-2026-64919 | Medium | 0.3% | 7.8 | Stack-based buffer overflow in Microsoft Office Access allows an unauthorized at… | |
| CVE-2026-64920 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized att… | |
| CVE-2026-68803 | Medium | 0.3% | 7.8 | Access of resource using incompatible type ('type confusion') in Microsoft Offic… | |
| CVE-2026-68807 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… | |
| CVE-2026-68810 | Medium | 0.3% | 7.8 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized a… | |
| CVE-2026-68811 | Medium | 0.3% | 7.8 | Access of resource using incompatible type ('type confusion') in Microsoft Offic… | |
| CVE-2026-68815 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… | |
| CVE-2026-70311 | Medium | 0.3% | 7.8 | Use after free in Microsoft Office Word allows an unauthorized attacker to execu… | |
| CVE-2026-9927 | Medium | 0.3% | 8.8 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-9928 | Medium | 0.3% | 8.8 | Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 … | |
| CVE-2026-9945 | Medium | 0.3% | 8.8 | Use after free in Media in Google Chrome on Windows prior to 148.0.7778.216 allo… | |
| CVE-2026-9947 | Medium | 0.3% | 8.8 | Use after free in XML in Google Chrome prior to 148.0.7778.216 allowed a remote … | |
| CVE-2026-11042 | Medium | 0.3% | 8.8 | Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-11047 | Medium | 0.3% | 9.6 | Inappropriate implementation in Base in Google Chrome on Windows prior to 149.0.… | |
| CVE-2026-42901 | Medium | 0.3% | 10.0 | Origin validation error in Microsoft Entra ID allows an unauthorized attacker to… | |
| CVE-2026-9873 | Medium | 0.3% | 8.8 | Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a rem… | |
| CVE-2026-49171 | Medium | 0.3% | 7.5 | Use after free in Microsoft Windows Speech allows an authorized attacker to elev… | |
| CVE-2026-69900 | Medium | 0.3% | 7.8 | Untrusted pointer dereference in Kernel Streaming WOW Thunk Service Driver allow… | |
| CVE-2026-34693 | Medium | 0.3% | 8.0 | Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are af… | |
| CVE-2026-40409 | Medium | 0.3% | 7.8 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege V… |