microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-11086 | Medium | 0.3% | 8.8 | Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 all… | |
| CVE-2026-11125 | Medium | 0.3% | 8.8 | Use after free in Compositing in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-11130 | Medium | 0.3% | 8.8 | Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-11136 | Medium | 0.3% | 8.8 | Use after free in Canvas in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-11164 | Medium | 0.3% | 8.8 | Use after free in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-11171 | Medium | 0.3% | 8.8 | Integer overflow in Blink in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-11173 | Medium | 0.3% | 8.8 | Out of bounds write in V8 in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-11211 | Medium | 0.3% | 8.8 | Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote … | |
| CVE-2026-11262 | Medium | 0.3% | 8.8 | Use after free in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-9957 | Medium | 0.3% | 8.8 | Use after free in PDF in Google Chrome prior to 148.0.7778.216 allowed a remote … | |
| CVE-2026-9968 | Medium | 0.3% | 8.8 | Integer overflow in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote… | |
| CVE-2026-50307 | Medium | 0.3% | 7.0 | Use after free in Windows TCP/IP allows an authorized attacker to elevate privil… | |
| CVE-2026-50358 | Medium | 0.3% | 7.0 | Use after free in Windows Media allows an authorized attacker to elevate privile… | |
| CVE-2026-50359 | Medium | 0.3% | 7.0 | Use after free in Microsoft XML Core Services allows an authorized attacker to e… | |
| CVE-2026-50390 | Medium | 0.3% | 7.0 | Access of resource using incompatible type ('type confusion') in Windows Kernel … | |
| CVE-2026-50393 | Medium | 0.3% | 7.0 | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to e… | |
| CVE-2026-50396 | Medium | 0.3% | 7.0 | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to e… | |
| CVE-2026-50406 | Medium | 0.3% | 7.0 | Use after free in Windows Backup Engine allows an authorized attacker to elevate… | |
| CVE-2026-50476 | Medium | 0.3% | 7.8 | Use after free in Microsoft Windows allows an authorized attacker to elevate pri… | |
| CVE-2026-50490 | Medium | 0.3% | 7.0 | Use after free in Windows Installer allows an authorized attacker to elevate pri… | |
| CVE-2026-50491 | Medium | 0.3% | 7.0 | Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker … | |
| CVE-2026-50674 | Medium | 0.3% | 7.0 | Use after free in Windows USB Print Driver allows an authorized attacker to elev… | |
| CVE-2026-54129 | Medium | 0.3% | 7.0 | Use after free in Windows Hyper-V allows an authorized attacker to elevate privi… | |
| CVE-2026-54989 | Medium | 0.3% | 7.0 | Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows … | |
| CVE-2026-56187 | Medium | 0.3% | 7.0 | Use after free in Windows MIDI Service Module allows an authorized attacker to e… | |
| CVE-2026-57093 | Medium | 0.3% | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-87585 | Medium | 0.3% | 8.8 | Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allo… | |
| CVE-2026-11030 | Medium | 0.3% | 8.8 | Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-11037 | Medium | 0.3% | 9.6 | Out of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-61356 | Medium | 0.3% | 7.8 | Missing authentication for critical function in Windows Remote Desktop Services … | |
| CVE-2026-61364 | Medium | 0.3% | 7.8 | Missing authentication for critical function in Windows Remote Desktop Services … | |
| CVE-2026-61365 | Medium | 0.3% | 7.8 | Missing authentication for critical function in Windows Remote Desktop Services … | |
| CVE-2026-61367 | Medium | 0.3% | 7.8 | Missing authentication for critical function in Windows Remote Desktop Services … | |
| CVE-2026-69907 | Medium | 0.3% | 7.8 | Improper handling of insufficient permissions or privileges in Windows Enterpris… | |
| CVE-2026-83990 | Medium | 0.3% | 7.8 | Stack-based buffer overflow in Microsoft Graphics Component allows an authorized… | |
| CVE-2026-84000 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Graphics Component allows an authorized … | |
| CVE-2026-47911 | Medium | 0.3% | 7.8 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-56181 | Medium | 0.3% | 8.3 | Origin validation error in Windows Network Address Translation (NAT) allows an u… | |
| CVE-2026-84351 | Medium | 0.3% | 8.3 | Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 all… | |
| CVE-2026-87648 | Medium | 0.3% | 8.3 | Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 al… | |
| CVE-2026-11641 | Medium | 0.3% | 7.5 | Use after free in Bluetooth in Google Chrome on Windows prior to 149.0.7827.103 … | |
| CVE-2026-35558 | Medium | 0.3% | 7.8 | Improper neutralization of special elements in the authentication components in … | |
| CVE-2026-41108 | Medium | 0.3% | 7.0 | Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacke… | |
| CVE-2026-11191 | Medium | 0.3% | 8.8 | Out of bounds memory access in ANGLE in Google Chrome prior to 149.0.7827.53 all… | |
| CVE-2026-21277 | Medium | 0.3% | 7.8 | InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based … | |
| CVE-2026-21304 | Medium | 0.3% | 7.8 | InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based … | |
| CVE-2026-27311 | Medium | 0.3% | 7.8 | Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer O… | |
| CVE-2026-27312 | Medium | 0.3% | 7.8 | Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer O… | |
| CVE-2026-40417 | Medium | 0.3% | 7.8 | Weak authentication in Dynamics Business Central allows an authorized attacker t… | |
| CVE-2026-11643 | Medium | 0.3% | 8.1 | Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remot… |