microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2024-21376 | Medium | 1.2% | 9.0 | Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution … | |
| CVE-2026-49181 | Medium | 1.2% | 7.5 | Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthor… | |
| CVE-2026-48286 | Medium | 1.2% | 10.0 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected … | |
| CVE-2021-26431 | Medium | 1.2% | 7.8 | Windows Recovery Environment Agent Elevation of Privilege Vulnerability | |
| CVE-2026-54117 | Medium | 1.2% | 9.8 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker … | |
| CVE-2026-54118 | Medium | 1.2% | 9.8 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker … | |
| CVE-2024-38263 | Medium | 1.2% | 7.5 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | |
| CVE-2021-26862 | Medium | 1.2% | 7.0 | Windows Installer Elevation of Privilege Vulnerability | |
| CVE-2024-21389 | Medium | 1.2% | 7.6 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| CVE-2024-21393 | Medium | 1.2% | 7.6 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| CVE-2024-21396 | Medium | 1.2% | 7.6 | Dynamics 365 Sales Spoofing Vulnerability | |
| CVE-2022-41118 | Medium | 1.2% | 7.5 | Windows Scripting Languages Remote Code Execution Vulnerability | |
| CVE-2023-21686 | Medium | 1.2% | 8.8 | Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerabilit… | |
| CVE-2023-21808 | Medium | 1.1% | 7.8 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2021-26866 | Medium | 1.1% | 7.1 | Windows Update Service Elevation of Privilege Vulnerability | |
| CVE-2026-77484 | Medium | 1.1% | 8.8 | Deserialization of untrusted data in SQL Server allows an authorized attacker to… | |
| CVE-2021-36963 | Medium | 1.1% | 7.8 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2022-41120 | Medium | 1.1% | 7.8 | Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability | |
| CVE-2024-21395 | Medium | 1.1% | 8.2 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| CVE-2020-1070 | Medium | 1.1% | 7.8 | An elevation of privilege vulnerability exists when the Windows Print Spooler se… | |
| CVE-2021-26873 | Medium | 1.1% | 7.0 | Windows User Profile Service Elevation of Privilege Vulnerability | |
| CVE-2026-20856 | Medium | 1.1% | 8.1 | Improper input validation in Windows Server Update Service allows an unauthorize… | |
| CVE-2026-54113 | Medium | 1.1% | 7.5 | Allocation of resources without limits or throttling in Windows Kernel allows an… | |
| CVE-2026-69342 | Medium | 1.1% | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to den… | |
| CVE-2026-69428 | Medium | 1.1% | 7.5 | Out-of-bounds read in Windows LDAP - Lightweight Directory Access Protocol allow… | |
| CVE-2026-77895 | Medium | 1.1% | 7.5 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to den… | |
| CVE-2026-45648 | Medium | 1.1% | 8.8 | Stack-based buffer overflow in Active Directory Domain Services allows an author… | |
| CVE-2022-41057 | Medium | 1.1% | 7.8 | Windows HTTP.sys Elevation of Privilege Vulnerability | |
| CVE-2024-43467 | Medium | 1.1% | 7.5 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | |
| CVE-2024-21394 | Medium | 1.1% | 7.6 | Dynamics 365 Field Service Spoofing Vulnerability | |
| CVE-2023-21705 | Medium | 1.1% | 8.8 | Microsoft SQL Server Remote Code Execution Vulnerability | |
| CVE-2026-62898 | Medium | 1.1% | 7.5 | Use after free in Microsoft QUIC allows an unauthorized attacker to disclose inf… | |
| CVE-2022-41039 | Medium | 1.1% | 8.1 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | |
| CVE-2026-56186 | Medium | 1.1% | 8.1 | Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose… | |
| CVE-2026-57108 | Medium | 1.1% | 7.5 | Access of resource using incompatible type ('type confusion') in .NET Core allow… | |
| CVE-2026-20854 | Medium | 1.1% | 7.5 | Use after free in Windows Local Security Authority Subsystem Service (LSASS) all… | |
| CVE-2026-20922 | Medium | 1.1% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to exec… | |
| CVE-2026-44815 | Medium | 1.1% | 9.8 | Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attack… | |
| CVE-2026-66808 | Medium | 1.1% | 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an autho… | |
| CVE-2026-50515 | Medium | 1.1% | 9.9 | Deserialization of untrusted data in Azure Service Bus allows an authorized atta… | |
| CVE-2023-21717 | Medium | 1.1% | 8.8 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | |
| CVE-2024-21329 | Medium | 1.1% | 7.3 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | |
| CVE-2021-26889 | Medium | 1.1% | 7.8 | Windows Update Stack Elevation of Privilege Vulnerability | |
| CVE-2021-42296 | Medium | 1.1% | 7.8 | Microsoft Word Remote Code Execution Vulnerability | |
| CVE-2021-34483 | Medium | 1.1% | 7.8 | Windows Print Spooler Elevation of Privilege Vulnerability | |
| CVE-2020-1143 | Medium | 1.1% | 7.0 | An elevation of privilege vulnerability exists in Windows when the Windows kerne… | |
| CVE-2026-50429 | Medium | 1.1% | 8.2 | Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose… | |
| CVE-2023-23374 | Medium | 1.1% | 8.3 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| CVE-2021-26865 | Medium | 1.1% | 8.8 | Windows Container Execution Agent Elevation of Privilege Vulnerability | |
| CVE-2022-41044 | Medium | 1.1% | 8.1 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability |