microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2024-43460 | Medium | 0.7% | 8.1 | Improper authorization in Dynamics 365 Business Central resulted in a vulnerabil… | |
| CVE-2021-26864 | Medium | 0.7% | 8.4 | Windows Virtual Registry Provider Elevation of Privilege Vulnerability | |
| CVE-2026-54120 | Medium | 0.7% | 9.9 | Improper input validation in Microsoft Surface allows an authorized attacker to … | |
| CVE-2026-58275 | Medium | 0.7% | 10.0 | Missing authorization in Azure DNS allows an unauthorized attacker to elevate pr… | |
| CVE-2026-62792 | Medium | 0.7% | 8.1 | Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to… | |
| CVE-2026-62825 | Medium | 0.7% | 10.0 | Improper authentication in Azure Key Vault allows an unauthorized attacker to el… | |
| CVE-2026-69620 | Medium | 0.7% | 8.1 | Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attack… | |
| CVE-2026-69989 | Medium | 0.7% | 8.1 | Use after free in DNS Server allows an unauthorized attacker to execute code ove… | |
| CVE-2022-41085 | Medium | 0.7% | 7.5 | Azure CycleCloud Elevation of Privilege Vulnerability | |
| CVE-2026-50686 | Medium | 0.7% | 8.1 | Access of resource using incompatible type ('type confusion') in Windows OLE all… | |
| CVE-2026-33120 | Medium | 0.7% | 8.8 | Untrusted pointer dereference in SQL Server allows an authorized attacker to exe… | |
| CVE-2026-32186 | Medium | 0.7% | 10.0 | Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized atta… | |
| CVE-2026-33107 | Medium | 0.7% | 10.0 | Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized at… | |
| CVE-2026-67368 | Medium | 0.7% | 8.8 | Improper link resolution before file access ('link following') in SQL Server all… | |
| CVE-2026-69332 | Medium | 0.7% | 8.0 | Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate priv… | |
| CVE-2026-69423 | Medium | 0.7% | 8.0 | Heap-based buffer overflow in Windows USB Video Driver allows an authorized atta… | |
| CVE-2026-69727 | Medium | 0.7% | 8.0 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-69773 | Medium | 0.7% | 8.0 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-69826 | Medium | 0.7% | 8.0 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-50369 | Medium | 0.7% | 8.8 | Use after free in Windows Remote Desktop Services allows an authorized attacker … | |
| CVE-2021-26426 | Medium | 0.7% | 7.0 | Windows User Account Profile Picture Elevation of Privilege Vulnerability | |
| CVE-2021-40447 | Medium | 0.7% | 7.8 | Windows Print Spooler Elevation of Privilege Vulnerability | |
| CVE-2024-38250 | Medium | 0.7% | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability | |
| CVE-2026-48323 | Medium | 0.7% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia… | |
| CVE-2026-66304 | Medium | 0.7% | 7.5 | Server-side request forgery (ssrf) in Skype for Business allows an unauthorized … | |
| CVE-2026-70324 | Medium | 0.7% | 8.8 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an auth… | |
| CVE-2024-38046 | Medium | 0.7% | 7.8 | PowerShell Elevation of Privilege Vulnerability | |
| CVE-2024-38247 | Medium | 0.7% | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability | |
| CVE-2026-20837 | Medium | 0.7% | 7.8 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to e… | |
| CVE-2026-59113 | Medium | 0.7% | 8.8 | Missing authorization in Visual Studio Code allows an unauthorized attacker to e… | |
| CVE-2021-26870 | Medium | 0.7% | 7.8 | Windows Projected File System Elevation of Privilege Vulnerability | |
| CVE-2021-26872 | Medium | 0.7% | 7.8 | Windows Event Tracing Elevation of Privilege Vulnerability | |
| CVE-2021-26880 | Medium | 0.7% | 7.8 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | |
| CVE-2023-38170 | Medium | 0.7% | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | |
| CVE-2026-48330 | Medium | 0.7% | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia… | |
| CVE-2021-34514 | Medium | 0.7% | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2026-81383 | Medium | 0.7% | 7.4 | Use of incorrectly-resolved name or reference in Visual Studio Code allows an un… | |
| CVE-2026-58595 | Medium | 0.7% | 8.1 | Improper restriction of rendered ui layers or frames in Microsoft Bing App for I… | |
| CVE-2026-45481 | Medium | 0.7% | 7.3 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-69858 | Medium | 0.7% | 8.1 | Use after free in Windows DNS allows an unauthorized attacker to execute code ov… | |
| CVE-2026-69510 | Medium | 0.7% | 8.1 | Stack-based buffer overflow in Windows DHCP Server allows an unauthorized attack… | |
| CVE-2026-62910 | Medium | 0.7% | 7.2 | Improper control of resource identifiers ('resource injection') in Microsoft Exc… | |
| CVE-2021-41372 | Medium | 0.7% | 7.6 | A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability… | |
| CVE-2026-67380 | Medium | 0.7% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execut… | |
| CVE-2026-67638 | Medium | 0.7% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execut… | |
| CVE-2026-67639 | Medium | 0.7% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execut… | |
| CVE-2026-76193 | Medium | 0.7% | 10.0 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF)… | |
| CVE-2026-40376 | Medium | 0.7% | 7.5 | Improper input validation in Visual Studio Code allows an unauthorized attacker … | |
| CVE-2026-67631 | Medium | 0.7% | 9.8 | Heap-based buffer overflow in SQL Server allows an unauthorized attacker to exec… | |
| CVE-2026-47298 | Medium | 0.7% | 8.0 | Improper authorization in Microsoft Office SharePoint allows an authorized attac… |