microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2023-21778 | Medium | 1.0% | 8.0 | Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability | |
| CVE-2021-26899 | Medium | 1.0% | 7.8 | Windows UPnP Device Host Elevation of Privilege Vulnerability | |
| CVE-2026-47301 | Medium | 1.0% | 8.8 | Improper access control in Microsoft Configuration Manager allows an authorized … | |
| CVE-2026-48449 | Medium | 1.0% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi… | |
| CVE-2026-56196 | Medium | 1.0% | 8.8 | Relative path traversal in Windows Admin Center allows an authorized attacker to… | |
| CVE-2026-47289 | Medium | 1.0% | 8.8 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac… | |
| CVE-2026-70296 | Medium | 1.0% | 9.8 | Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker… | |
| CVE-2026-77493 | Medium | 1.0% | 9.8 | Double free in Microsoft Graphics Component allows an unauthorized attacker to e… | |
| CVE-2026-78509 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized at… | |
| CVE-2026-78510 | Medium | 1.0% | 9.8 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attac… | |
| CVE-2024-35248 | Medium | 1.0% | 7.3 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | |
| CVE-2024-38249 | Medium | 1.0% | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability | |
| CVE-2020-1068 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists in Windows Media Service that all… | |
| CVE-2020-1081 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when the Windows Printer Service … | |
| CVE-2020-1110 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when the Windows Update Stack fai… | |
| CVE-2020-1111 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when Windows improperly handles c… | |
| CVE-2020-1114 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when the Windows kernel fails to … | |
| CVE-2020-1137 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists in the way the Windows Push Notif… | |
| CVE-2020-1140 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when DirectX improperly handles o… | |
| CVE-2020-1142 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists in the way that the Windows Graph… | |
| CVE-2020-1154 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when the Windows Common Log File … | |
| CVE-2020-1165 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when Windows improperly handles c… | |
| CVE-2020-1166 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists when Windows improperly handles c… | |
| CVE-2026-59133 | Medium | 0.9% | 8.8 | Execution with unnecessary privileges in Microsoft High Performance Computing (H… | |
| CVE-2021-34510 | Medium | 0.9% | 7.8 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | |
| CVE-2026-47299 | Medium | 0.9% | 7.2 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2026-50663 | Medium | 0.9% | 8.8 | Relative path traversal in Age of Empires II: Definitive Edition Game allows an … | |
| CVE-2020-1021 | Medium | 0.9% | 7.8 | An elevation of privilege vulnerability exists in Windows Error Reporting (WER) … | |
| CVE-2026-21229 | Medium | 0.9% | 8.0 | Improper input validation in Power BI allows an authorized attacker to execute c… | |
| CVE-2026-50649 | Medium | 0.9% | 7.8 | Deserialization of untrusted data in .NET allows an unauthorized attacker to exe… | |
| CVE-2024-43463 | Medium | 0.9% | 7.8 | Microsoft Office Visio Remote Code Execution Vulnerability | |
| CVE-2026-62784 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv)… | |
| CVE-2026-62800 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker t… | |
| CVE-2026-69845 | Medium | 0.9% | 9.8 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacke… | |
| CVE-2026-50682 | Medium | 0.9% | 7.1 | Out-of-bounds read in Windows Active Directory allows an authorized attacker to … | |
| CVE-2026-65815 | Medium | 0.9% | 8.8 | Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows… | |
| CVE-2026-48351 | Medium | 0.9% | 7.5 | CAI Content Credentials is affected by an Improper Input Validation vulnerabilit… | |
| CVE-2026-48352 | Medium | 0.9% | 7.5 | CAI Content Credentials is affected by an Improper Input Validation vulnerabilit… | |
| CVE-2023-21568 | Medium | 0.9% | 7.3 | Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vu… | |
| CVE-2021-1729 | Medium | 0.9% | 7.1 | Windows Update Stack Setup Elevation of Privilege Vulnerability | |
| CVE-2024-38216 | Medium | 0.9% | 8.2 | Azure Stack Hub Elevation of Privilege Vulnerability | |
| CVE-2026-41104 | Medium | 0.9% | 10.0 | Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an … | |
| CVE-2026-56197 | Medium | 0.9% | 8.8 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2026-69716 | Medium | 0.9% | 8.8 | Improper neutralization of special elements used in an sql command ('sql injecti… | |
| CVE-2026-69464 | Medium | 0.9% | 8.8 | Execution with unnecessary privileges in Microsoft Office SharePoint allows an a… | |
| CVE-2026-69551 | Medium | 0.9% | 8.8 | Use after free in Windows DNS allows an authorized attacker to execute code over… | |
| CVE-2026-32213 | Medium | 0.9% | 10.0 | Improper authorization in Azure AI Foundry allows an unauthorized attacker to el… | |
| CVE-2026-49178 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Active Directory Domain Services allows an authori… | |
| CVE-2026-50666 | Medium | 0.9% | 8.8 | Use after free in Windows Remote Access Connection Manager allows an authorized … | |
| CVE-2026-56194 | Medium | 0.9% | 8.8 | Heap-based buffer overflow in Windows Network File System allows an authorized a… |