microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-57106 | Medium | 0.5% | 10.0 | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attack… | |
| CVE-2026-48333 | Medium | 0.5% | 9.8 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi… | |
| CVE-2026-20941 | Medium | 0.5% | 7.8 | Improper link resolution before file access ('link following') in Host Process f… | |
| CVE-2026-59118 | Medium | 0.5% | 9.3 | Improper authorization in Copilot Cowork allows an unauthorized attacker to elev… | |
| CVE-2026-5860 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remot… | |
| CVE-2026-17691 | Medium | 0.5% | 9.6 | Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 … | |
| CVE-2024-43492 | Medium | 0.5% | 7.8 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | |
| CVE-2026-48331 | Medium | 0.5% | 10.0 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF)… | |
| CVE-2026-62735 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to … | |
| CVE-2026-20870 | Medium | 0.5% | 7.8 | Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevat… | |
| CVE-2026-20938 | Medium | 0.5% | 7.8 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enc… | |
| CVE-2026-33843 | Medium | 0.5% | 9.1 | Authentication bypass using an alternate path or channel in Microsoft Azure Acti… | |
| CVE-2026-35561 | Medium | 0.5% | 7.4 | Insufficient authentication security controls in the browser-based authenticatio… | |
| CVE-2026-42913 | Medium | 0.5% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-66309 | Medium | 0.5% | 9.1 | Improper access control in Azure SQL Database allows an authorized attacker to e… | |
| CVE-2026-80081 | Medium | 0.5% | 8.8 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to… | |
| CVE-2026-80085 | Medium | 0.5% | 8.8 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attac… | |
| CVE-2026-49176 | Medium | 0.5% | 7.8 | Improper privilege management in Windows WalletService allows an authorized atta… | |
| CVE-2026-62896 | Medium | 0.5% | 9.6 | Improper authentication in Microsoft Teams allows an authorized attacker to elev… | |
| CVE-2026-13473 | Medium | 0.5% | 8.1 | IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 throu… | |
| CVE-2026-50364 | Medium | 0.5% | 7.3 | Improper link resolution before file access ('link following') in Windows Server… | |
| CVE-2026-77898 | Medium | 0.5% | 7.5 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t… | |
| CVE-2026-10882 | Medium | 0.5% | 8.8 | Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-49796 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to ex… | |
| CVE-2026-49797 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-50308 | Medium | 0.5% | 7.8 | Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized at… | |
| CVE-2026-50313 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-50386 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-50388 | Medium | 0.5% | 7.8 | Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute co… | |
| CVE-2026-50448 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-50461 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-50471 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-50655 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to e… | |
| CVE-2026-54124 | Medium | 0.5% | 7.8 | Integer overflow or wraparound in Windows Terminal allows an unauthorized attack… | |
| CVE-2026-55133 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized at… | |
| CVE-2026-58609 | Medium | 0.5% | 7.8 | Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attack… | |
| CVE-2026-58610 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unaut… | |
| CVE-2026-69855 | Medium | 0.5% | 7.7 | Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an autho… | |
| CVE-2026-79019 | Medium | 0.5% | 9.6 | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.… | |
| CVE-2026-48399 | Medium | 0.5% | 7.5 | Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Princip… | |
| CVE-2026-58630 | Medium | 0.5% | 10.0 | Improper access control in Azure App Service allows an unauthorized attacker to … | |
| CVE-2026-20940 | Medium | 0.5% | 7.8 | Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an a… | |
| CVE-2026-70355 | Medium | 0.5% | 7.3 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-42992 | Medium | 0.5% | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac… | |
| CVE-2026-44799 | Medium | 0.5% | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac… | |
| CVE-2026-44801 | Medium | 0.5% | 7.5 | Use after free in Remote Desktop Client allows an unauthorized attacker to execu… | |
| CVE-2026-56161 | Medium | 0.5% | 9.6 | Improper access control in Azure Logic Apps allows an authorized attacker to dis… | |
| CVE-2026-50462 | Medium | 0.5% | 7.8 | External control of file name or path in Windows Ancillary Function Driver for W… | |
| CVE-2026-7347 | Medium | 0.5% | 8.1 | Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a … | |
| CVE-2026-10939 | Medium | 0.5% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… |