microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-11665 | Low | 0.2% | 4.3 | Out of bounds read in Dawn in Google Chrome on Windows prior to 149.0.7827.103 a… | |
| CVE-2026-5881 | Low | 0.2% | 6.5 | Policy bypass in LocalNetworkAccess in Google Chrome prior to 147.0.7727.55 allo… | |
| CVE-2026-73004 | Low | 0.2% | 5.5 | Missing authentication for critical function in Windows Autopilot allows an auth… | |
| CVE-2026-11193 | Low | 0.2% | 6.5 | Insufficient policy enforcement in Password Manager in Google Chrome prior to 14… | |
| CVE-2026-45647 | Low | 0.2% | 5.5 | Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endp… | |
| CVE-2026-11014 | Low | 0.2% | 6.5 | Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.78… | |
| CVE-2026-11666 | Low | 0.2% | 5.4 | Insufficient validation of untrusted input in Input in Google Chrome prior to 14… | |
| CVE-2026-8447 | Low | 0.2% | 6.1 | IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting … | |
| CVE-2026-61928 | Low | 0.2% | 5.5 | Cleartext storage of sensitive information in Windows Hello allows an authorized… | |
| CVE-2026-11069 | Low | 0.2% | 6.5 | Insufficient validation of untrusted input in Cast in Google Chrome prior to 149… | |
| CVE-2026-9907 | Low | 0.2% | 4.3 | Out of bounds read in Dawn in Google Chrome on Windows prior to 148.0.7778.216 a… | |
| CVE-2026-77887 | Low | 0.2% | 6.4 | Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execu… | |
| CVE-2026-77891 | Low | 0.2% | 6.4 | Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execu… | |
| CVE-2026-11174 | Low | 0.2% | 5.3 | Inappropriate implementation in Site Isolation in Google Chrome prior to 149.0.7… | |
| CVE-2026-11244 | Low | 0.2% | 3.1 | Insufficient validation of untrusted input in WebAuthentication in Google Chrome… | |
| CVE-2026-21288 | Low | 0.2% | 5.5 | Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Der… | |
| CVE-2026-5891 | Low | 0.2% | 4.3 | Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.77… | |
| CVE-2026-11166 | Low | 0.2% | 6.8 | Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-7360 | Low | 0.2% | 3.1 | Insufficient validation of untrusted input. in Compositing in Google Chrome prio… | |
| CVE-2026-11031 | Low | 0.2% | 4.3 | Insufficient validation of untrusted input in Password Manager in Google Chrome … | |
| CVE-2026-11132 | Low | 0.2% | 6.5 | Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-11133 | Low | 0.2% | 6.5 | Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-11162 | Low | 0.2% | 4.3 | Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-11246 | Low | 0.2% | 5.3 | Insufficient validation of untrusted input in IndexedDB in Google Chrome prior t… | |
| CVE-2026-11078 | Low | 0.2% | 6.5 | Inappropriate implementation in FileSystem in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-11135 | Low | 0.2% | 6.5 | Insufficient policy enforcement in Autofill in Google Chrome prior to 149.0.7827… | |
| CVE-2026-11142 | Low | 0.2% | 6.5 | Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-11197 | Low | 0.2% | 6.5 | Insufficient policy enforcement in Workers in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-11258 | Low | 0.2% | 6.5 | Inappropriate implementation in File System Access in Google Chrome prior to 149… | |
| CVE-2026-11218 | Low | 0.2% | 6.8 | Inappropriate implementation in PlatformIntegration in Google Chrome on Windows … | |
| CVE-2026-11675 | Low | 0.2% | 3.1 | Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a re… | |
| CVE-2026-17627 | Low | 0.2% | 4.9 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacke… | |
| CVE-2026-9942 | Low | 0.2% | 5.0 | Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re… | |
| CVE-2026-11299 | Low | 0.2% | 6.5 | Integer overflow in Fonts in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-11288 | Low | 0.2% | 6.5 | Insufficient policy enforcement in CSS in Google Chrome prior to 149.0.7827.53 a… | |
| CVE-2026-11289 | Low | 0.2% | 6.5 | Side-channel information leakage in Paint in Google Chrome prior to 149.0.7827.5… | |
| CVE-2026-8852 | Low | 0.2% | 6.2 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional… | |
| CVE-2026-9944 | Low | 0.2% | 3.1 | Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re… | |
| CVE-2026-34705 | Low | 0.2% | 5.5 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bou… | |
| CVE-2026-11038 | Low | 0.2% | 6.5 | Insufficient policy enforcement in Subresource Integrity in Google Chrome prior … | |
| CVE-2026-11696 | Low | 0.2% | 5.3 | Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.103 a… | |
| CVE-2026-12702 | Low | 0.2% | 4.9 | In affected versions of Octopus Deploy Insufficient checks on the project trigge… | |
| CVE-2026-8673 | Low | 0.2% | 5.9 | Unprotected transport of credentials vulnerability in syslink software AG Avantr… | |
| CVE-2026-10018 | Low | 0.2% | 6.5 | Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a rem… | |
| CVE-2026-5878 | Low | 0.2% | 4.3 | Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a… | |
| CVE-2026-5880 | Low | 0.2% | 4.3 | Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.77… | |
| CVE-2026-5882 | Low | 0.2% | 4.3 | Incorrect security UI in Fullscreen in Google Chrome prior to 147.0.7727.55 allo… | |
| CVE-2026-81993 | Low | 0.2% | 5.5 | Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that co… | |
| CVE-2026-9981 | Low | 0.2% | 6.5 | Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 al… | |
| CVE-2026-11195 | Low | 0.2% | 6.5 | Inappropriate implementation in MHTML in Google Chrome prior to 149.0.7827.53 al… |