microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-58535 | Low | 0.9% | 6.5 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to … | |
| CVE-2026-58539 | Low | 0.9% | 6.5 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose in… | |
| CVE-2026-58546 | Low | 0.9% | 6.5 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to … | |
| CVE-2026-72938 | Low | 0.9% | 6.5 | Access of resource using incompatible type ('type confusion') in Microsoft Offic… | |
| CVE-2026-72956 | Low | 0.9% | 6.5 | Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthori… | |
| CVE-2026-72974 | Low | 0.9% | 6.5 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to di… | |
| CVE-2026-78453 | Low | 0.9% | 6.5 | Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System Fi… | |
| CVE-2026-78503 | Low | 0.9% | 6.5 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to d… | |
| CVE-2026-78515 | Low | 0.9% | 6.5 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2026-80073 | Low | 0.9% | 6.5 | Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker t… | |
| CVE-2026-80079 | Low | 0.9% | 6.5 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to d… | |
| CVE-2026-80088 | Low | 0.9% | 6.5 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to d… | |
| CVE-2026-80089 | Low | 0.9% | 6.5 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclo… | |
| CVE-2026-47284 | Low | 0.9% | 6.5 | Exposure of sensitive information to an unauthorized actor in Visual Studio Code… | |
| CVE-2023-21722 | Low | 0.9% | 5.0 | .NET Framework Denial of Service Vulnerability | |
| CVE-2021-41376 | Low | 0.9% | 2.3 | Azure Sphere Information Disclosure Vulnerability | |
| CVE-2026-34348 | Low | 0.9% | 6.5 | Protection mechanism failure in Windows Event Logging Service allows an authoriz… | |
| CVE-2026-42903 | Low | 0.9% | 6.5 | Null pointer dereference in Windows Kerberos allows an authorized attacker to de… | |
| CVE-2021-38657 | Low | 0.9% | 6.1 | Microsoft Office Graphics Component Information Disclosure Vulnerability | |
| CVE-2021-41375 | Low | 0.9% | 4.4 | Azure Sphere Information Disclosure Vulnerability | |
| CVE-2026-69591 | Low | 0.9% | 5.7 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose inf… | |
| CVE-2026-69552 | Low | 0.9% | 5.7 | Generation of error message containing sensitive information in Windows Print Sp… | |
| CVE-2026-69572 | Low | 0.9% | 5.7 | Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclo… | |
| CVE-2021-36956 | Low | 0.9% | 4.4 | Azure Sphere Information Disclosure Vulnerability | |
| CVE-2023-21721 | Low | 0.9% | 6.5 | Microsoft OneNote Elevation of Privilege Vulnerability | |
| CVE-2021-33763 | Low | 0.9% | 5.5 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | |
| CVE-2021-34440 | Low | 0.9% | 5.5 | GDI+ Information Disclosure Vulnerability | |
| CVE-2021-34454 | Low | 0.9% | 5.5 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | |
| CVE-2021-34457 | Low | 0.9% | 5.5 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | |
| CVE-2021-36938 | Low | 0.9% | 5.5 | Windows Cryptographic Primitives Library Information Disclosure Vulnerability | |
| CVE-2021-36969 | Low | 0.9% | 5.5 | Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulne… | |
| CVE-2021-36972 | Low | 0.9% | 5.5 | Windows SMB Information Disclosure Vulnerability | |
| CVE-2021-38635 | Low | 0.9% | 5.5 | Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulne… | |
| CVE-2021-38636 | Low | 0.9% | 5.5 | Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulne… | |
| CVE-2021-38637 | Low | 0.9% | 5.5 | Windows Storage Information Disclosure Vulnerability | |
| CVE-2026-20824 | Low | 0.9% | 5.5 | Protection mechanism failure in Windows Remote Assistance allows an unauthorized… | |
| CVE-2026-47285 | Low | 0.9% | 6.5 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2026-61918 | Low | 0.9% | 6.5 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to d… | |
| CVE-2026-62782 | Low | 0.9% | 6.5 | Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disc… | |
| CVE-2026-69626 | Low | 0.9% | 6.5 | Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose… | |
| CVE-2026-69719 | Low | 0.9% | 6.5 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to dis… | |
| CVE-2026-69734 | Low | 0.9% | 6.5 | Integer overflow or wraparound in Microsoft Office Word allows an unauthorized a… | |
| CVE-2026-69739 | Low | 0.9% | 6.5 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclo… | |
| CVE-2026-62837 | Low | 0.9% | 6.5 | Relative path traversal in Microsoft Office SharePoint allows an authorized atta… | |
| CVE-2021-42277 | Low | 0.9% | 5.5 | Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability | |
| CVE-2026-50415 | Low | 0.9% | 5.3 | Exposure of sensitive information to an unauthorized actor in Windows Media allo… | |
| CVE-2026-69569 | Low | 0.9% | 5.7 | Untrusted pointer dereference in Windows Print Spooler Components allows an auth… | |
| CVE-2021-42303 | Low | 0.9% | 6.6 | Azure RTOS Elevation of Privilege Vulnerability | |
| CVE-2026-50324 | Low | 0.9% | 5.9 | Loop with unreachable exit condition ('infinite loop') in Active Directory Feder… | |
| CVE-2026-70327 | Low | 0.9% | 6.5 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … |