microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-36933 | Medium | 3.5% | 7.5 | Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | |
| CVE-2021-26885 | Medium | 3.5% | 7.8 | Windows WalletService Elevation of Privilege Vulnerability | |
| CVE-2021-34504 | Medium | 3.4% | 7.8 | Windows Address Book Remote Code Execution Vulnerability | |
| CVE-2024-35249 | Medium | 3.4% | 8.8 | Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability | |
| CVE-2021-34479 | Medium | 3.4% | 7.8 | Microsoft Visual Studio Spoofing Vulnerability | |
| CVE-2026-62696 | Medium | 3.4% | 7.8 | Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistan… | |
| CVE-2024-38237 | Medium | 3.4% | 7.8 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | |
| CVE-2024-38242 | Medium | 3.4% | 7.8 | Kernel Streaming Service Driver Elevation of Privilege Vulnerability | |
| CVE-2023-21812 | Medium | 3.3% | 7.8 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2026-62832 | Medium | 3.3% | 7.8 | Improper link resolution before file access ('link following') in Windows User P… | |
| CVE-2020-1061 | Medium | 3.3% | 7.5 | A remote code execution vulnerability exists in the way that the Microsoft Scrip… | |
| CVE-2020-1112 | Medium | 3.3% | 8.5 | An elevation of privilege vulnerability exists when the Windows Background Intel… | |
| CVE-2021-36960 | Medium | 3.3% | 7.5 | Windows SMB Information Disclosure Vulnerability | |
| CVE-2021-42306 | Medium | 3.3% | 8.1 | An information disclosure vulnerability manifests when a user or an application … | |
| CVE-2021-33772 | Medium | 3.3% | 7.5 | Windows TCP/IP Driver Denial of Service Vulnerability | |
| CVE-2021-33785 | Medium | 3.3% | 7.5 | Windows AF_UNIX Socket Provider Denial of Service Vulnerability | |
| CVE-2021-33788 | Medium | 3.3% | 7.5 | Windows LSA Denial of Service Vulnerability | |
| CVE-2021-34476 | Medium | 3.3% | 7.5 | Bowser.sys Denial of Service Vulnerability | |
| CVE-2021-34490 | Medium | 3.3% | 7.5 | Windows TCP/IP Driver Denial of Service Vulnerability | |
| CVE-2020-1150 | Medium | 3.2% | 7.8 | A memory corruption vulnerability exists when Windows Media Foundation improperl… | |
| CVE-2021-21009 | Medium | 3.2% | 8.6 | Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.… | |
| CVE-2021-27060 | Medium | 3.2% | 7.8 | Visual Studio Code Remote Code Execution Vulnerability | |
| CVE-2021-34442 | Medium | 3.1% | 8.8 | Windows DNS Server Remote Code Execution Vulnerability | |
| CVE-2020-1035 | Medium | 3.1% | 7.5 | A remote code execution vulnerability exists in the way that the VBScript engine… | |
| CVE-2020-1064 | Medium | 3.1% | 7.5 | A remote code execution vulnerability exists in the way that the MSHTML engine i… | |
| CVE-2020-1093 | Medium | 3.1% | 7.5 | A remote code execution vulnerability exists in the way that the VBScript engine… | |
| CVE-2021-34528 | Medium | 3.1% | 7.8 | Visual Studio Code Remote Code Execution Vulnerability | |
| CVE-2020-1058 | Medium | 3.1% | 7.5 | A remote code execution vulnerability exists in the way that the VBScript engine… | |
| CVE-2020-1060 | Medium | 3.1% | 7.5 | A remote code execution vulnerability exists in the way that the VBScript engine… | |
| CVE-2020-1092 | Medium | 3.1% | 7.5 | A remote code execution vulnerability exists when Internet Explorer improperly a… | |
| CVE-2021-26868 | Medium | 3.1% | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability | |
| CVE-2021-26859 | Medium | 3.0% | 7.7 | Microsoft Power BI Information Disclosure Vulnerability | |
| CVE-2023-35383 | Medium | 3.0% | 7.5 | Microsoft Message Queuing Information Disclosure Vulnerability | |
| CVE-2021-41356 | Medium | 3.0% | 7.5 | Windows Denial of Service Vulnerability | |
| CVE-2026-20929 | Medium | 2.9% | 7.5 | Improper access control in Windows HTTP.sys allows an authorized attacker to ele… | |
| CVE-2026-63520 | Medium | 2.9% | 8.1 | Improper input validation in Microsoft Office SharePoint allows an unauthorized … | |
| CVE-2021-33758 | Medium | 2.8% | 7.7 | Windows Hyper-V Denial of Service Vulnerability | |
| CVE-2026-62737 | Medium | 2.8% | 7.8 | Untrusted pointer dereference in Windows Kernel allows an authorized attacker to… | |
| CVE-2021-26867 | Medium | 2.8% | 9.9 | Windows Hyper-V Remote Code Execution Vulnerability | |
| CVE-2026-65665 | Medium | 2.8% | 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an autho… | |
| CVE-2021-33740 | Medium | 2.7% | 7.8 | Windows Media Remote Code Execution Vulnerability | |
| CVE-2026-62893 | Medium | 2.7% | 9.8 | Use after free in Windows Deployment Services allows an unauthorized attacker to… | |
| CVE-2021-34449 | Medium | 2.7% | 7.0 | Win32k Elevation of Privilege Vulnerability | |
| CVE-2021-26876 | Medium | 2.7% | 8.8 | OpenType Font Parsing Remote Code Execution Vulnerability | |
| CVE-2021-33780 | Medium | 2.7% | 8.8 | Windows DNS Server Remote Code Execution Vulnerability | |
| CVE-2024-21404 | Medium | 2.7% | 7.5 | .NET Denial of Service Vulnerability | |
| CVE-2021-34522 | Medium | 2.7% | 7.8 | Microsoft Defender Remote Code Execution Vulnerability | |
| CVE-2021-26861 | Medium | 2.7% | 7.8 | Windows Graphics Component Remote Code Execution Vulnerability | |
| CVE-2021-27047 | Medium | 2.7% | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | |
| CVE-2023-38185 | Medium | 2.7% | 8.8 | Microsoft Exchange Server Remote Code Execution Vulnerability |