microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-72995 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-73000 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-73002 | Medium | 0.2% | 7.8 | Integer overflow or wraparound in Windows Biometric Service allows an authorized… | |
| CVE-2026-73007 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-73011 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-73015 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-73020 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-73024 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows … | |
| CVE-2026-73026 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-77904 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Volume Manager Extension Driver allows an … | |
| CVE-2026-78447 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-78448 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83952 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an aut… | |
| CVE-2026-83955 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83969 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83974 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83976 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-11250 | Medium | 0.2% | 9.6 | Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-34630 | Medium | 0.2% | 7.8 | Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer O… | |
| CVE-2026-49161 | Medium | 0.2% | 7.8 | Improper access control in Microsoft PC Manager allows an authorized attacker to… | |
| CVE-2026-61349 | Medium | 0.2% | 7.8 | Use after free in Windows Work Folder Service allows an authorized attacker to e… | |
| CVE-2026-81354 | Medium | 0.2% | 8.2 | Heap-based buffer overflow in Windows Hello allows an authorized attacker to ele… | |
| CVE-2026-69501 | Medium | 0.2% | 7.0 | Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized… | |
| CVE-2026-11303 | Medium | 0.2% | 8.8 | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-21274 | Medium | 0.2% | 7.8 | Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Autho… | |
| CVE-2026-49805 | Medium | 0.2% | 7.0 | Improper access control in Windows Win32K allows an authorized attacker to eleva… | |
| CVE-2026-50297 | Medium | 0.2% | 7.0 | Improper access control in Windows Win32K allows an authorized attacker to eleva… | |
| CVE-2026-50325 | Medium | 0.2% | 7.0 | Improper access control in Windows Win32K allows an authorized attacker to eleva… | |
| CVE-2026-68847 | Medium | 0.2% | 7.0 | Use after free in Windows Connected User Experiences and Telemetry allows an aut… | |
| CVE-2026-69864 | Medium | 0.2% | 7.8 | Use after free in Windows Hello allows an authorized attacker to elevate privile… | |
| CVE-2026-48349 | Medium | 0.2% | 8.1 | Animate is affected by an Incorrect Authorization vulnerability that could resul… | |
| CVE-2026-9960 | Medium | 0.2% | 7.5 | Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a re… | |
| CVE-2026-10021 | Medium | 0.2% | 8.8 | Insufficient validation of untrusted input in USB in Google Chrome prior to 148.… | |
| CVE-2026-11041 | Medium | 0.2% | 8.8 | Insufficient validation of untrusted input in Media in Google Chrome on Windows … | |
| CVE-2026-11056 | Medium | 0.2% | 9.6 | Insufficient validation of untrusted input in SiteIsolation in Google Chrome on … | |
| CVE-2026-11063 | Medium | 0.2% | 9.6 | Insufficient validation of untrusted input in WebNN in Google Chrome on Windows … | |
| CVE-2026-11094 | Medium | 0.2% | 9.6 | Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.53 allo… | |
| CVE-2026-11124 | Medium | 0.2% | 8.8 | Integer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-11146 | Medium | 0.2% | 9.6 | Insufficient validation of untrusted input in Chromoting in Google Chrome prior … | |
| CVE-2026-11152 | Medium | 0.2% | 9.6 | Object lifecycle issue in Dawn in Google Chrome prior to 149.0.7827.53 allowed a… | |
| CVE-2026-11177 | Medium | 0.2% | 8.8 | Use after free in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-21221 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-21357 | Medium | 0.2% | 7.8 | InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based … | |
| CVE-2026-27313 | Medium | 0.2% | 7.8 | Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer O… | |
| CVE-2026-34335 | Medium | 0.2% | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-42911 | Medium | 0.2% | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-45640 | Medium | 0.2% | 7.0 | Use after free in Windows Bluetooth Port Driver allows an authorized attacker to… | |
| CVE-2026-47293 | Medium | 0.2% | 7.0 | Use after free in Microsoft Office Click-To-Run allows an authorized attacker to… | |
| CVE-2026-56179 | Medium | 0.2% | 8.3 | Origin validation error in Windows Network Address Translation (NAT) allows an u… | |
| CVE-2026-9874 | Medium | 0.2% | 9.6 | Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote… |