microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2023-21800 | Medium | 1.1% | 7.8 | Windows Installer Elevation of Privilege Vulnerability | |
| CVE-2026-62901 | Medium | 1.1% | 7.5 | Unchecked input for loop condition in .NET allows an unauthorized attacker to de… | |
| CVE-2021-26887 | Medium | 1.1% | 7.8 | An elevation of privilege vulnerability exists in Microsoft Windows when Folder … | |
| CVE-2023-35387 | Medium | 1.1% | 8.8 | Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability | |
| CVE-2021-34498 | Medium | 1.0% | 7.8 | Windows GDI Elevation of Privilege Vulnerability | |
| CVE-2021-34512 | Medium | 1.0% | 7.8 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | |
| CVE-2021-34513 | Medium | 1.0% | 7.8 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | |
| CVE-2023-21695 | Medium | 1.0% | 7.5 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execut… | |
| CVE-2026-69525 | Medium | 1.0% | 9.8 | Use after free in Windows Remote Desktop Services allows an unauthorized attacke… | |
| CVE-2023-36895 | Medium | 1.0% | 7.8 | Microsoft Outlook Remote Code Execution Vulnerability | |
| CVE-2026-78461 | Medium | 1.0% | 7.4 | Improper limitation of a pathname to a restricted directory ('path traversal') i… | |
| CVE-2026-48567 | Medium | 1.0% | 10.0 | Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized atta… | |
| CVE-2026-69829 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to e… | |
| CVE-2024-38220 | Medium | 1.0% | 9.0 | Azure Stack Hub Elevation of Privilege Vulnerability | |
| CVE-2026-47302 | Medium | 1.0% | 7.5 | Allocation of resources without limits or throttling in .NET allows an unauthori… | |
| CVE-2026-48573 | Medium | 1.0% | 7.9 | No cwe for this issue in Windows Secure Boot allows an authorized attacker to by… | |
| CVE-2026-48576 | Medium | 1.0% | 7.9 | No cwe for this issue in Windows Secure Boot allows an authorized attacker to by… | |
| CVE-2026-50463 | Medium | 1.0% | 7.5 | Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose… | |
| CVE-2026-50470 | Medium | 1.0% | 7.5 | Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized … | |
| CVE-2026-69443 | Medium | 1.0% | 7.5 | Out-of-bounds read in Windows Device Health Attestation (DHA) allows an unauthor… | |
| CVE-2026-20849 | Medium | 1.0% | 7.5 | Reliance on untrusted inputs in a security decision in Windows Kerberos allows a… | |
| CVE-2026-81385 | Medium | 1.0% | 8.8 | Deserialization of untrusted data in Microsoft Office Publisher allows an unauth… | |
| CVE-2021-38633 | Medium | 1.0% | 7.8 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2026-48579 | Medium | 1.0% | 9.1 | Improper authorization in Microsoft Exchange Online allows an unauthorized attac… | |
| CVE-2026-55005 | Medium | 1.0% | 8.8 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized att… | |
| CVE-2026-56170 | Medium | 1.0% | 7.5 | Allocation of resources without limits or throttling in ASP.NET Core allows an u… | |
| CVE-2022-41088 | Medium | 1.0% | 8.1 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | |
| CVE-2026-69496 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized a… | |
| CVE-2026-64921 | Medium | 1.0% | 8.8 | Missing authentication for critical function in Microsoft Office SharePoint allo… | |
| CVE-2026-47295 | Medium | 1.0% | 8.8 | Improper neutralization of special elements used in an sql command ('sql injecti… | |
| CVE-2020-1079 | Medium | 1.0% | 7.8 | An elevation of privilege vulnerability exists when the Windows fails to properl… | |
| CVE-2023-35371 | Medium | 1.0% | 7.8 | Microsoft Office Remote Code Execution Vulnerability | |
| CVE-2023-35372 | Medium | 1.0% | 7.8 | Microsoft Office Visio Remote Code Execution Vulnerability | |
| CVE-2023-36896 | Medium | 1.0% | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | |
| CVE-2020-1109 | Medium | 1.0% | 7.8 | An elevation of privilege vulnerability exists when the Windows Update Stack fai… | |
| CVE-2020-1082 | Medium | 1.0% | 7.8 | An elevation of privilege vulnerability exists in Windows Error Reporting (WER) … | |
| CVE-2026-42990 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized atta… | |
| CVE-2026-49172 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacke… | |
| CVE-2026-50447 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows Message Queuing allows an unauthorized att… | |
| CVE-2026-50518 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacke… | |
| CVE-2026-55010 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unaut… | |
| CVE-2026-56159 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacke… | |
| CVE-2026-56190 | Medium | 1.0% | 9.8 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to … | |
| CVE-2026-69910 | Medium | 1.0% | 9.8 | Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker t… | |
| CVE-2026-8476 | Medium | 1.0% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution v… | |
| CVE-2020-1010 | Medium | 1.0% | 7.8 | An elevation of privilege vulnerability exists in Windows Block Level Backup Eng… | |
| CVE-2020-1135 | Medium | 1.0% | 7.8 | An elevation of privilege vulnerability exists when the Windows Graphics Compone… | |
| CVE-2026-62818 | Medium | 1.0% | 8.8 | Use after free in Active Directory Certificate Services (AD CS) allows an author… | |
| CVE-2026-72979 | Medium | 1.0% | 9.8 | Use after free in Windows DHCP Server allows an unauthorized attacker to execute… | |
| CVE-2026-50646 | Medium | 1.0% | 7.8 | Protection mechanism failure in .NET Framework allows an unauthorized attacker t… |