microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-41374 | Low | 0.7% | 6.7 | Azure Sphere Information Disclosure Vulnerability | |
| CVE-2023-21794 | Low | 0.7% | 4.3 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | |
| CVE-2024-43612 | Low | 0.7% | 6.9 | Power BI Report Server Spoofing Vulnerability | |
| CVE-2021-26430 | Low | 0.7% | 6.0 | Azure Sphere Denial of Service Vulnerability | |
| CVE-2026-73019 | Low | 0.7% | 4.3 | Improper resolution of path equivalence in Windows URL Moniker allows an unautho… | |
| CVE-2024-38254 | Low | 0.7% | 5.5 | Windows Authentication Information Disclosure Vulnerability | |
| CVE-2021-33765 | Low | 0.7% | 6.2 | Windows Installer Spoofing Vulnerability | |
| CVE-2024-38235 | Low | 0.7% | 6.5 | Windows Hyper-V Denial of Service Vulnerability | |
| CVE-2024-38256 | Low | 0.7% | 5.5 | Windows Kernel-Mode Driver Information Disclosure Vulnerability | |
| CVE-2026-66816 | Low | 0.7% | 6.5 | Insufficient logging in SQL Server allows an authorized attacker to bypass a sec… | |
| CVE-2026-67386 | Low | 0.7% | 6.5 | Use of uninitialized resource in SQL Server allows an authorized attacker to dis… | |
| CVE-2026-67389 | Low | 0.7% | 6.5 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose infor… | |
| CVE-2026-68781 | Low | 0.7% | 6.5 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose infor… | |
| CVE-2026-68784 | Low | 0.7% | 6.5 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose infor… | |
| CVE-2026-20821 | Low | 0.7% | 6.2 | Exposure of sensitive information to an unauthorized actor in Windows Remote Pro… | |
| CVE-2026-62899 | Low | 0.7% | 5.9 | Inconsistent interpretation of http requests ('http request/response smuggling')… | |
| CVE-2026-78520 | Low | 0.7% | 6.5 | Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker t… | |
| CVE-2021-42288 | Low | 0.7% | 5.7 | Windows Hello Security Feature Bypass Vulnerability | |
| CVE-2026-56649 | Low | 0.7% | 5.9 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2021-42302 | Low | 0.7% | 6.6 | Azure RTOS Elevation of Privilege Vulnerability | |
| CVE-2021-42304 | Low | 0.7% | 6.6 | Azure RTOS Elevation of Privilege Vulnerability | |
| CVE-2023-36869 | Low | 0.7% | 6.3 | Azure DevOps Server Spoofing Vulnerability | |
| CVE-2026-72975 | Low | 0.7% | 6.5 | Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacke… | |
| CVE-2026-77911 | Low | 0.7% | 6.5 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to d… | |
| CVE-2026-78502 | Low | 0.7% | 6.5 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to d… | |
| CVE-2026-78522 | Low | 0.7% | 6.5 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to d… | |
| CVE-2026-80076 | Low | 0.7% | 6.5 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclo… | |
| CVE-2026-80078 | Low | 0.7% | 6.5 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclo… | |
| CVE-2026-80082 | Low | 0.7% | 6.5 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclo… | |
| CVE-2026-80084 | Low | 0.7% | 6.5 | Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker t… | |
| CVE-2026-80086 | Low | 0.7% | 6.5 | Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacke… | |
| CVE-2026-80087 | Low | 0.7% | 6.5 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t… | |
| CVE-2026-80090 | Low | 0.7% | 6.5 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to d… | |
| CVE-2026-80091 | Low | 0.7% | 6.5 | Use of uninitialized resource in Microsoft Office allows an unauthorized attacke… | |
| CVE-2026-20932 | Low | 0.7% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explo… | |
| CVE-2025-29821 | Low | 0.7% | 5.5 | Improper input validation in Dynamics Business Central allows an authorized atta… | |
| CVE-2021-42274 | Low | 0.7% | 6.8 | Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability | |
| CVE-2026-66301 | Low | 0.7% | 6.5 | Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics… | |
| CVE-2026-68819 | Low | 0.7% | 5.9 | Buffer over-read in Windows Network File System allows an unauthorized attacker … | |
| CVE-2026-20823 | Low | 0.7% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explo… | |
| CVE-2026-20827 | Low | 0.7% | 5.5 | Exposure of sensitive information to an unauthorized actor in Tablet Windows Use… | |
| CVE-2026-20838 | Low | 0.7% | 5.5 | Generation of error message containing sensitive information in Windows Kernel a… | |
| CVE-2026-69415 | Low | 0.7% | 6.8 | Missing authentication for critical function in Windows DHCP Server allows an au… | |
| CVE-2022-38015 | Low | 0.7% | 6.5 | Windows Hyper-V Denial of Service Vulnerability | |
| CVE-2026-65769 | Low | 0.7% | 6.5 | Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mo… | |
| CVE-2026-50485 | Low | 0.7% | 4.5 | Buffer over-read in Windows Hyper-V allows an authorized attacker to deny servic… | |
| CVE-2026-70091 | Low | 0.7% | 5.9 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2023-21807 | Low | 0.7% | 6.5 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| CVE-2026-20828 | Low | 0.7% | 4.6 | Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauth… | |
| CVE-2026-66324 | Low | 0.7% | 6.5 | External control of file name or path in Microsoft Edge (Chromium-based) allows … |