microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-81947 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… | |
| CVE-2026-81954 | Medium | 0.3% | 7.8 | Use after free in Microsoft Office Excel allows an unauthorized attacker to exec… | |
| CVE-2026-87618 | Medium | 0.3% | 8.3 | Incorrect reference resolution in Storage in Google Chrome on on Windows prior t… | |
| CVE-2024-21355 | Medium | 0.3% | 7.0 | Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | |
| CVE-2026-50488 | Medium | 0.3% | 7.8 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2026-58635 | Medium | 0.3% | 7.8 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2026-65673 | Medium | 0.3% | 7.8 | Improper neutralization of special elements used in an sql command ('sql injecti… | |
| CVE-2026-69543 | Medium | 0.3% | 8.5 | Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorize… | |
| CVE-2026-70307 | Medium | 0.3% | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-81356 | Medium | 0.3% | 8.2 | Inconsistent interpretation of http requests ('http request/response smuggling')… | |
| CVE-2026-81378 | Medium | 0.3% | 8.2 | Interpretation conflict in Visual Studio Code allows an unauthorized attacker to… | |
| CVE-2026-81379 | Medium | 0.3% | 8.2 | Not failing securely ('failing open') in Visual Studio Code allows an unauthoriz… | |
| CVE-2026-59119 | Medium | 0.3% | 7.3 | Incorrect default permissions in Microsoft PowerShell allows an authorized attac… | |
| CVE-2026-32222 | Medium | 0.3% | 7.8 | Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized att… | |
| CVE-2026-10013 | Medium | 0.3% | 8.8 | Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a r… | |
| CVE-2026-45656 | Medium | 0.3% | 7.8 | Protection mechanism failure in Windows UEFI allows an authorized attacker to by… | |
| CVE-2026-69820 | Medium | 0.3% | 8.2 | Heap-based buffer overflow in Windows Hello allows an authorized attacker to ele… | |
| CVE-2026-7353 | Medium | 0.3% | 8.3 | Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.138 allowed a … | |
| CVE-2026-9938 | Medium | 0.3% | 8.8 | Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allo… | |
| CVE-2026-20853 | Medium | 0.3% | 7.4 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-69846 | Medium | 0.3% | 8.2 | Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorize… | |
| CVE-2026-69906 | Medium | 0.3% | 8.2 | Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized at… | |
| CVE-2026-7346 | Medium | 0.3% | 8.1 | Inappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 al… | |
| CVE-2026-11015 | Medium | 0.3% | 8.1 | Out of bounds read in WebGPU in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-33114 | Medium | 0.3% | 8.4 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized at… | |
| CVE-2026-33115 | Medium | 0.3% | 8.4 | Use after free in Microsoft Office Word allows an unauthorized attacker to execu… | |
| CVE-2022-41045 | Medium | 0.3% | 7.8 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerabilit… | |
| CVE-2022-41100 | Medium | 0.3% | 7.8 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerabilit… | |
| CVE-2026-11649 | Medium | 0.3% | 8.8 | Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote a… | |
| CVE-2026-11650 | Medium | 0.3% | 8.8 | Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote a… | |
| CVE-2026-48342 | Medium | 0.3% | 7.8 | Bridge is affected by an Integer Overflow or Wraparound vulnerability that could… | |
| CVE-2026-11076 | Medium | 0.3% | 8.8 | Type Confusion in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote a… | |
| CVE-2026-9878 | Medium | 0.3% | 8.8 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-56172 | Medium | 0.3% | 7.8 | Use after free in Windows VHD miniport driver allows an authorized attacker to e… | |
| CVE-2026-56177 | Medium | 0.3% | 7.8 | Use after free in Windows Server allows an authorized attacker to elevate privil… | |
| CVE-2026-59127 | Medium | 0.3% | 7.8 | Integer overflow or wraparound in Windows Installer allows an authorized attacke… | |
| CVE-2026-61353 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Telephony Service allows an authorized att… | |
| CVE-2026-61355 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Sensor Data Service allows an authorized a… | |
| CVE-2026-61357 | Medium | 0.3% | 7.8 | Use after free in Application Information Services allows an authorized attacker… | |
| CVE-2026-61923 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Display Enhancement Service allows an auth… | |
| CVE-2026-61926 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows USB Driver allows an authorized attacker t… | |
| CVE-2026-61932 | Medium | 0.3% | 7.8 | Access of resource using incompatible type ('type confusion') in Windows DWM Cor… | |
| CVE-2026-61934 | Medium | 0.3% | 7.8 | Use after free in Windows Bind Filter Driver allows an authorized attacker to el… | |
| CVE-2026-61937 | Medium | 0.3% | 7.8 | Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker… | |
| CVE-2026-62692 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Remote Desktop Services allows an authoriz… | |
| CVE-2026-62695 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Storage allows an authorized attacker to e… | |
| CVE-2026-62697 | Medium | 0.3% | 7.8 | Use after free in Windows Push Notifications allows an authorized attacker to el… | |
| CVE-2026-62700 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elev… | |
| CVE-2026-62701 | Medium | 0.3% | 7.8 | Use after free in Windows Telephony Service allows an authorized attacker to ele… | |
| CVE-2026-62707 | Medium | 0.3% | 7.8 | Use after free in Windows Modern Device Management (MDM) allows an authorized at… |