microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-50327 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Media allows an authorized attacker to exe… | |
| CVE-2026-50329 | Medium | 0.3% | 7.8 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-50331 | Medium | 0.3% | 7.8 | Use after free in Windows Application Model allows an authorized attacker to ele… | |
| CVE-2026-50332 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to el… | |
| CVE-2026-50336 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Media allows an authorized attacker to ele… | |
| CVE-2026-50337 | Medium | 0.3% | 7.8 | Incorrect type conversion or cast in Windows Notification allows an authorized a… | |
| CVE-2026-50353 | Medium | 0.3% | 7.8 | Use after free in Windows DirectX allows an authorized attacker to elevate privi… | |
| CVE-2026-50354 | Medium | 0.3% | 7.1 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-50363 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Push Notifications allows an authorized at… | |
| CVE-2026-50367 | Medium | 0.3% | 7.8 | Incorrect access of indexable resource ('range error') in Windows Sensor Data Se… | |
| CVE-2026-50382 | Medium | 0.3% | 8.8 | Untrusted pointer dereference in Windows DirectX allows an authorized attacker t… | |
| CVE-2026-50387 | Medium | 0.3% | 7.8 | Stack-based buffer overflow in Windows GDI allows an authorized attacker to elev… | |
| CVE-2026-50399 | Medium | 0.3% | 7.8 | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate pr… | |
| CVE-2026-50400 | Medium | 0.3% | 7.8 | Stack-based buffer overflow in Windows App Installer allows an authorized attack… | |
| CVE-2026-50402 | Medium | 0.3% | 7.8 | Incorrect conversion between numeric types in Windows NTFS allows an authorized … | |
| CVE-2026-50413 | Medium | 0.3% | 8.8 | Use after free in Windows Runtime allows an authorized attacker to elevate privi… | |
| CVE-2026-50417 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to exec… | |
| CVE-2026-50421 | Medium | 0.3% | 7.8 | Access of resource using incompatible type ('type confusion') in Windows Connect… | |
| CVE-2026-50425 | Medium | 0.3% | 7.8 | Use after free in Windows Internal System User Profile allows an authorized atta… | |
| CVE-2026-50433 | Medium | 0.3% | 7.8 | Use after free in Windows Media allows an authorized attacker to elevate privile… | |
| CVE-2026-50435 | Medium | 0.3% | 7.8 | Buffer over-read in Windows Overlay Filter allows an authorized attacker to elev… | |
| CVE-2026-50436 | Medium | 0.3% | 7.8 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-50441 | Medium | 0.3% | 7.8 | Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an … | |
| CVE-2026-50466 | Medium | 0.3% | 7.8 | Use after free in Windows Brokering File System allows an authorized attacker to… | |
| CVE-2026-50477 | Medium | 0.3% | 8.8 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to el… | |
| CVE-2026-50478 | Medium | 0.3% | 7.8 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-50479 | Medium | 0.3% | 7.8 | Untrusted pointer dereference in Windows USB Hub Driver allows an authorized att… | |
| CVE-2026-50480 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) a… | |
| CVE-2026-50484 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to el… | |
| CVE-2026-50486 | Medium | 0.3% | 7.8 | Use after free in Windows Runtime allows an authorized attacker to elevate privi… | |
| CVE-2026-50489 | Medium | 0.3% | 8.8 | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to el… | |
| CVE-2026-50493 | Medium | 0.3% | 7.8 | Use after free in Windows Graphics Kernel allows an authorized attacker to eleva… | |
| CVE-2026-50494 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to exec… | |
| CVE-2026-50499 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Print Spooler Components allows an authori… | |
| CVE-2026-50679 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Windows Search Component allows an autho… | |
| CVE-2026-50687 | Medium | 0.3% | 8.8 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-50692 | Medium | 0.3% | 8.8 | Heap-based buffer overflow in Desktop Window Manager allows an authorized attack… | |
| CVE-2026-54109 | Medium | 0.3% | 7.8 | Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an… | |
| CVE-2026-54114 | Medium | 0.3% | 7.8 | Use after free in Windows Win32K allows an authorized attacker to elevate privil… | |
| CVE-2026-54115 | Medium | 0.3% | 7.8 | Integer overflow or wraparound in Windows Active Directory allows an authorized … | |
| CVE-2026-54987 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Overlay Filter allows an authorized attack… | |
| CVE-2026-55004 | Medium | 0.3% | 7.8 | Double free in Microsoft Printer Drivers allows an authorized attacker to elevat… | |
| CVE-2026-56175 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elev… | |
| CVE-2026-56176 | Medium | 0.3% | 7.8 | Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to ele… | |
| CVE-2026-56182 | Medium | 0.3% | 7.8 | Integer overflow or wraparound in Windows NTFS allows an authorized attacker to … | |
| CVE-2026-56643 | Medium | 0.3% | 7.8 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-56644 | Medium | 0.3% | 7.8 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-56650 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Network File System allows an authorized a… | |
| CVE-2026-57091 | Medium | 0.3% | 7.8 | Stack-based buffer overflow in Windows File History Service allows an authorized… | |
| CVE-2026-57096 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) a… |