microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-67378 | Medium | 0.5% | 9.0 | Untrusted pointer dereference in SQL Server allows an unauthorized attacker to e… | |
| CVE-2026-67636 | Medium | 0.5% | 9.0 | Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code… | |
| CVE-2026-78444 | Medium | 0.5% | 8.1 | Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized… | |
| CVE-2026-78450 | Medium | 0.5% | 8.1 | Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unautho… | |
| CVE-2026-56169 | Medium | 0.5% | 8.1 | Improper authentication in Windows Admin Center allows an authorized attacker to… | |
| CVE-2026-62778 | Medium | 0.5% | 8.1 | Use after free in Windows DNS allows an unauthorized attacker to elevate privile… | |
| CVE-2021-34471 | Medium | 0.5% | 7.8 | Microsoft Defender Elevation of Privilege Vulnerability | |
| CVE-2026-57990 | Medium | 0.5% | 7.4 | Files or directories accessible to external parties in Microsoft Edge (Chromium-… | |
| CVE-2026-5865 | Medium | 0.5% | 8.8 | Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote at… | |
| CVE-2026-78462 | Medium | 0.5% | 8.8 | Authorization bypass through user-controlled key in Visual Studio Code allows an… | |
| CVE-2026-65802 | Medium | 0.5% | 7.4 | External control of file name or path in Microsoft Edge for Android allows an un… | |
| CVE-2026-83997 | Medium | 0.5% | 8.1 | Use after free in Windows Message Queuing allows an unauthorized attacker to exe… | |
| CVE-2026-9120 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remo… | |
| CVE-2026-20920 | Medium | 0.5% | 7.8 | Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevat… | |
| CVE-2026-47288 | Medium | 0.5% | 7.1 | Integer overflow or wraparound in Windows Kerberos allows an authorized attacker… | |
| CVE-2026-47296 | Medium | 0.5% | 7.5 | Improper neutralization of special elements used in an sql command ('sql injecti… | |
| CVE-2026-65675 | Medium | 0.5% | 7.1 | No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an una… | |
| CVE-2026-69777 | Medium | 0.5% | 8.0 | Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker … | |
| CVE-2026-48326 | Medium | 0.5% | 9.9 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia… | |
| CVE-2026-47632 | Medium | 0.5% | 8.8 | Improper certificate validation in Azure Connected Machine Agent allows an unaut… | |
| CVE-2021-34537 | Medium | 0.5% | 7.8 | Windows Bluetooth Driver Elevation of Privilege Vulnerability | |
| CVE-2026-20811 | Medium | 0.5% | 7.8 | Access of resource using incompatible type ('type confusion') in Windows Win32K … | |
| CVE-2026-47280 | Medium | 0.5% | 10.0 | Improper authentication in Azure Resource Manager (ARM) allows an unauthorized a… | |
| CVE-2026-56163 | Medium | 0.5% | 10.0 | Missing authentication for critical function in Microsoft Azure Kubernetes Servi… | |
| CVE-2026-87512 | Medium | 0.5% | 9.6 | Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 al… | |
| CVE-2026-10903 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-10943 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-10947 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-10948 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-19298 | Medium | 0.5% | 8.8 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke… | |
| CVE-2026-67381 | Medium | 0.5% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to elevat… | |
| CVE-2026-67385 | Medium | 0.5% | 8.8 | Use after free in SQL Server allows an authorized attacker to execute code over … | |
| CVE-2026-67388 | Medium | 0.5% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execut… | |
| CVE-2026-67642 | Medium | 0.5% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execut… | |
| CVE-2026-68775 | Medium | 0.5% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execut… | |
| CVE-2026-68786 | Medium | 0.5% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execut… | |
| CVE-2026-17692 | Medium | 0.5% | 9.6 | Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.7… | |
| CVE-2026-69412 | Medium | 0.5% | 8.0 | Stack-based buffer overflow in Windows DHCP Server allows an authorized attacker… | |
| CVE-2026-69847 | Medium | 0.5% | 8.0 | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker … | |
| CVE-2026-48317 | Medium | 0.5% | 9.6 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Direct… | |
| CVE-2021-36957 | Medium | 0.5% | 7.8 | Windows Desktop Bridge Elevation of Privilege Vulnerability | |
| CVE-2021-41366 | Medium | 0.5% | 7.8 | Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege V… | |
| CVE-2021-41367 | Medium | 0.5% | 7.8 | NTFS Elevation of Privilege Vulnerability | |
| CVE-2021-41370 | Medium | 0.5% | 7.8 | NTFS Elevation of Privilege Vulnerability | |
| CVE-2021-41377 | Medium | 0.5% | 7.8 | Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | |
| CVE-2021-42283 | Medium | 0.5% | 8.8 | NTFS Elevation of Privilege Vulnerability | |
| CVE-2021-42286 | Medium | 0.5% | 7.8 | Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of… | |
| CVE-2026-20832 | Medium | 0.5% | 7.8 | Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of P… | |
| CVE-2026-20857 | Medium | 0.5% | 7.8 | Untrusted pointer dereference in Windows Cloud Files Mini Filter Driver allows a… | |
| CVE-2026-20859 | Medium | 0.5% | 7.8 | Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to e… |