microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-69288 | Low | 0.3% | 5.5 | Use of uninitialized resource in Windows GDI+ allows an authorized attacker to d… | |
| CVE-2026-62887 | Low | 0.3% | 5.5 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose inf… | |
| CVE-2026-68851 | Low | 0.3% | 5.5 | Buffer over-read in Windows NTFS allows an authorized attacker to disclose infor… | |
| CVE-2026-69316 | Low | 0.3% | 4.7 | Buffer over-read in Windows Overlay Filter allows an authorized attacker to disc… | |
| CVE-2026-69369 | Low | 0.3% | 5.5 | Out-of-bounds read in Windows DNS allows an authorized attacker to disclose info… | |
| CVE-2026-69853 | Low | 0.3% | 4.7 | Use of uninitialized resource in Windows Win32K allows an authorized attacker to… | |
| CVE-2026-69895 | Low | 0.3% | 4.7 | Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to dis… | |
| CVE-2026-77488 | Low | 0.3% | 5.5 | Integer underflow (wrap or wraparound) in SQL Server allows an authorized attack… | |
| CVE-2026-9138 | Low | 0.3% | 6.5 | IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated atta… | |
| CVE-2026-50375 | Low | 0.3% | 6.3 | Heap-based buffer overflow in Windows DirectX allows an authorized attacker to e… | |
| CVE-2026-17621 | Low | 0.3% | 5.4 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse … | |
| CVE-2026-47924 | Low | 0.3% | 5.5 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-66323 | Low | 0.3% | 5.4 | Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chro… | |
| CVE-2026-70331 | Low | 0.3% | 5.4 | Improper neutralization of input used for llm prompting in Microsoft Edge for iO… | |
| CVE-2026-63521 | Low | 0.3% | 5.5 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to d… | |
| CVE-2026-77491 | Low | 0.3% | 5.5 | Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose in… | |
| CVE-2026-48354 | Low | 0.3% | 6.2 | CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnera… | |
| CVE-2026-32220 | Low | 0.3% | 4.4 | Improper access control in Windows Virtualization-Based Security (VBS) Enclave a… | |
| CVE-2026-65777 | Low | 0.3% | 5.3 | Inadequate encryption strength in Windows Active Directory allows an authorized … | |
| CVE-2026-19301 | Low | 0.3% | 5.0 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke… | |
| CVE-2026-5867 | Low | 0.3% | 4.3 | Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a … | |
| CVE-2026-11027 | Low | 0.3% | 6.5 | Insufficient validation of untrusted input in Glic in Google Chrome prior to 149… | |
| CVE-2026-11045 | Low | 0.3% | 6.5 | Insufficient validation of untrusted input in GPU in Google Chrome prior to 149.… | |
| CVE-2026-59131 | Low | 0.3% | 5.6 | No cwe for this issue in AMD Zen allows an authorized attacker to disclose infor… | |
| CVE-2026-65680 | Low | 0.3% | 6.7 | Improper link resolution before file access ('link following') in Microsoft OneD… | |
| CVE-2026-48312 | Low | 0.3% | 6.8 | CAI Content Credentials is affected by an Improper Input Validation vulnerabilit… | |
| CVE-2026-61936 | Low | 0.3% | 5.5 | Missing authorization in Windows Defender Firewall Service allows an authorized … | |
| CVE-2026-35199 | Low | 0.3% | 6.1 | SymCrypt is the core cryptographic function library currently used by Windows. F… | |
| CVE-2026-47923 | Low | 0.3% | 5.5 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-72966 | Low | 0.3% | 5.5 | Missing authorization in Windows Remote Access Connection Manager allows an auth… | |
| CVE-2026-10912 | Low | 0.3% | 6.5 | Insufficient validation of untrusted input in Extensions in Google Chrome prior … | |
| CVE-2026-11016 | Low | 0.3% | 6.5 | Insufficient validation of untrusted input in Network in Google Chrome prior to … | |
| CVE-2026-11018 | Low | 0.3% | 6.5 | Insufficient policy enforcement in Actor in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-11022 | Low | 0.3% | 6.5 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to… | |
| CVE-2026-21331 | Low | 0.3% | 6.1 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cro… | |
| CVE-2026-68830 | Low | 0.3% | 5.5 | Improper link resolution before file access ('link following') in Windows Univer… | |
| CVE-2026-66311 | Low | 0.3% | 6.2 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized … | |
| CVE-2026-62904 | Low | 0.3% | 5.4 | Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorize… | |
| CVE-2026-66809 | Low | 0.3% | 5.5 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclo… | |
| CVE-2026-66810 | Low | 0.3% | 5.5 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attac… | |
| CVE-2026-68809 | Low | 0.3% | 5.5 | Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacke… | |
| CVE-2026-70310 | Low | 0.3% | 5.5 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to d… | |
| CVE-2026-70312 | Low | 0.3% | 5.5 | Improper input validation in Microsoft Office PowerPoint allows an unauthorized … | |
| CVE-2026-10571 | Low | 0.3% | 5.7 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected… | |
| CVE-2026-11004 | Low | 0.3% | 5.3 | Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a re… | |
| CVE-2026-11005 | Low | 0.3% | 5.3 | Out of bounds read in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 a… | |
| CVE-2026-27222 | Low | 0.3% | 5.4 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vuln… | |
| CVE-2026-35559 | Low | 0.3% | 6.5 | Out-of-bounds write in the query processing components in Amazon Athena ODBC dri… | |
| CVE-2026-9186 | Low | 0.3% | 6.5 | IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to b… | |
| CVE-2026-11017 | Low | 0.3% | 6.5 | Inappropriate implementation in Link Preview in Google Chrome prior to 149.0.782… |