microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-20819 | Low | 0.6% | 5.5 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enc… | |
| CVE-2026-50659 | Low | 0.6% | 6.5 | Improper encoding or escaping of output in .NET allows an authorized attacker to… | |
| CVE-2026-62900 | Low | 0.5% | 5.9 | Improper removal of sensitive information before storage or transfer in .NET all… | |
| CVE-2026-63512 | Low | 0.5% | 6.5 | Incorrect authorization in Microsoft Office SharePoint allows an authorized atta… | |
| CVE-2026-32226 | Low | 0.5% | 5.9 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-57083 | Low | 0.5% | 5.5 | Use of uninitialized resource in Microsoft Windows Codecs Library allows an unau… | |
| CVE-2026-57084 | Low | 0.5% | 5.5 | Use of uninitialized resource in Windows File Explorer allows an unauthorized at… | |
| CVE-2026-78506 | Low | 0.5% | 5.5 | Improper null termination in Microsoft Office Word allows an unauthorized attack… | |
| CVE-2026-78513 | Low | 0.5% | 5.5 | Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacke… | |
| CVE-2026-20825 | Low | 0.5% | 4.4 | Improper access control in Windows Hyper-V allows an authorized attacker to disc… | |
| CVE-2026-62814 | Low | 0.5% | 6.5 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthor… | |
| CVE-2026-62801 | Low | 0.5% | 6.5 | Improper limitation of a pathname to a restricted directory ('path traversal') i… | |
| CVE-2026-70105 | Low | 0.5% | 6.5 | Improper input validation in Microsoft Office Word allows an unauthorized attack… | |
| CVE-2026-55145 | Low | 0.5% | 6.3 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2026-58528 | Low | 0.5% | 6.8 | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an un… | |
| CVE-2026-32223 | Low | 0.5% | 6.8 | Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized at… | |
| CVE-2026-33113 | Low | 0.5% | 5.4 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-20876 | Low | 0.5% | 6.7 | Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclav… | |
| CVE-2026-20939 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explo… | |
| CVE-2026-45453 | Low | 0.5% | 5.4 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-45465 | Low | 0.5% | 5.4 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-47636 | Low | 0.5% | 5.4 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-47639 | Low | 0.5% | 5.4 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-50453 | Low | 0.5% | 6.1 | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an un… | |
| CVE-2026-20937 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explo… | |
| CVE-2026-49807 | Low | 0.5% | 6.2 | Exposure of sensitive information to an unauthorized actor in Windows DirectX al… | |
| CVE-2026-50294 | Low | 0.5% | 6.2 | Exposure of sensitive system information to an unauthorized control sphere in Wi… | |
| CVE-2026-69781 | Low | 0.5% | 6.5 | Missing release of memory after effective lifetime in Windows DHCP Client allows… | |
| CVE-2026-45462 | Low | 0.5% | 4.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-45467 | Low | 0.5% | 4.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-45468 | Low | 0.5% | 4.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-45479 | Low | 0.5% | 4.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-45483 | Low | 0.5% | 4.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-47637 | Low | 0.5% | 4.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-47638 | Low | 0.5% | 4.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-47640 | Low | 0.5% | 4.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-47641 | Low | 0.5% | 4.6 | Improper input validation in Microsoft Office SharePoint allows an authorized at… | |
| CVE-2026-48562 | Low | 0.5% | 4.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-42827 | Low | 0.5% | 6.5 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2026-57097 | Low | 0.5% | 6.4 | Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass… | |
| CVE-2026-66306 | Low | 0.5% | 6.5 | Generation of error message containing sensitive information in Skype for Busine… | |
| CVE-2026-78455 | Low | 0.5% | 4.3 | Out-of-bounds read in Xbox allows an unauthorized attacker to disclose informati… | |
| CVE-2026-78516 | Low | 0.5% | 4.3 | Buffer over-read in Windows Storage allows an unauthorized attacker to disclose … | |
| CVE-2026-81392 | Low | 0.5% | 5.5 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2026-81395 | Low | 0.5% | 5.5 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2026-81401 | Low | 0.5% | 5.5 | Access of resource using incompatible type ('type confusion') in Microsoft Offic… | |
| CVE-2023-21697 | Low | 0.5% | 6.2 | Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulne… | |
| CVE-2024-21397 | Low | 0.5% | 5.3 | Microsoft Azure File Sync Elevation of Privilege Vulnerability | |
| CVE-2026-17707 | Low | 0.5% | 6.5 | Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 al… | |
| CVE-2024-38221 | Low | 0.5% | 4.3 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |