microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-42973 | Low | 0.4% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Push Notif… | |
| CVE-2026-45594 | Low | 0.4% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Applicatio… | |
| CVE-2026-49801 | Low | 0.4% | 5.5 | Use of uninitialized resource in Windows SMB allows an authorized attacker to di… | |
| CVE-2026-50300 | Low | 0.4% | 5.5 | Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized at… | |
| CVE-2026-50381 | Low | 0.4% | 5.5 | Access of resource using incompatible type ('type confusion') in Composite Image… | |
| CVE-2026-50383 | Low | 0.4% | 6.1 | Buffer over-read in Windows Print Spooler Components allows an authorized attack… | |
| CVE-2026-50401 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorize… | |
| CVE-2026-50437 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to … | |
| CVE-2026-50455 | Low | 0.4% | 5.5 | Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an au… | |
| CVE-2026-50690 | Low | 0.4% | 5.5 | Use of uninitialized resource in Windows SMB allows an authorized attacker to di… | |
| CVE-2026-58614 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a s… | |
| CVE-2026-70145 | Low | 0.4% | 5.5 | Out-of-bounds read in Microsoft Windows Search Component allows an authorized at… | |
| CVE-2026-70290 | Low | 0.4% | 5.5 | Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an author… | |
| CVE-2026-69690 | Low | 0.4% | 4.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-81390 | Low | 0.4% | 5.5 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2026-50657 | Low | 0.4% | 4.7 | Exposure of private personal information to an unauthorized actor in Microsoft D… | |
| CVE-2026-83949 | Low | 0.4% | 5.5 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to dis… | |
| CVE-2026-83951 | Low | 0.4% | 5.5 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to dis… | |
| CVE-2026-17706 | Low | 0.4% | 4.3 | Insufficient validation of untrusted input in Media in Google Chrome on Windows … | |
| CVE-2026-50684 | Low | 0.4% | 4.8 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-69615 | Low | 0.4% | 3.5 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-72976 | Low | 0.4% | 5.0 | Out-of-bounds read in Microsoft Office Word allows an authorized attacker to dis… | |
| CVE-2026-78454 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to dis… | |
| CVE-2026-81394 | Low | 0.4% | 5.5 | Exposure of sensitive system information to an unauthorized control sphere in Mi… | |
| CVE-2026-57980 | Low | 0.4% | 5.4 | Authentication bypass using an alternate path or channel in Microsoft Edge (Chro… | |
| CVE-2026-63523 | Low | 0.4% | 6.5 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-42968 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Telephony Service allows an authorized attacker to… | |
| CVE-2026-42969 | Low | 0.4% | 5.5 | Use of uninitialized resource in Windows Push Notifications allows an authorized… | |
| CVE-2026-45491 | Low | 0.4% | 6.2 | Improper link resolution before file access ('link following') in .NET allows an… | |
| CVE-2026-48566 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to … | |
| CVE-2026-59128 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized … | |
| CVE-2026-59137 | Low | 0.4% | 5.5 | Use of uninitialized resource in Windows Event Logging Service allows an authori… | |
| CVE-2026-61347 | Low | 0.4% | 5.5 | Buffer over-read in Windows Event Logging Service allows an authorized attacker … | |
| CVE-2026-61360 | Low | 0.4% | 5.5 | Untrusted pointer dereference in Windows GDI allows an authorized attacker to di… | |
| CVE-2026-61933 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to … | |
| CVE-2026-62703 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to … | |
| CVE-2026-62709 | Low | 0.4% | 5.5 | Use of uninitialized resource in Windows GDI+ allows an authorized attacker to d… | |
| CVE-2026-62730 | Low | 0.4% | 5.5 | Buffer over-read in Windows Wired AutoConfig Service allows an authorized attack… | |
| CVE-2026-62738 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Management Instrumentation allows an authorized at… | |
| CVE-2026-62740 | Low | 0.4% | 5.5 | Use of uninitialized resource in Windows Imaging Component allows an authorized … | |
| CVE-2026-62743 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose i… | |
| CVE-2026-62746 | Low | 0.4% | 5.5 | Buffer over-read in Windows Win32K allows an authorized attacker to disclose inf… | |
| CVE-2026-69286 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an au… | |
| CVE-2026-69318 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Imaging Component allows an authorized attacker to… | |
| CVE-2026-69343 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Overlay Filter allows an authorized attacker to di… | |
| CVE-2026-69344 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Print Spooler Components allows an authorized atta… | |
| CVE-2026-69390 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to dis… | |
| CVE-2026-69457 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows USB Driver allows an authorized attacker to disclo… | |
| CVE-2026-69504 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose inf… | |
| CVE-2026-69527 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows USB Mass Storage Class Driver allows an authorized… |