microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-48581 | Medium | 0.3% | 7.8 | Insufficient granularity of access control in Microsoft Surface allows an author… | |
| CVE-2026-49170 | Medium | 0.3% | 7.8 | Insufficient granularity of access control in Windows StateRepository API allows… | |
| CVE-2026-50311 | Medium | 0.3% | 7.8 | Improper access control in Windows Server allows an authorized attacker to eleva… | |
| CVE-2026-50333 | Medium | 0.3% | 7.8 | Missing authentication for critical function in Windows Spaceport.sys allows an … | |
| CVE-2026-50335 | Medium | 0.3% | 7.8 | Improper access control in Windows Operating Systems allows an authorized attack… | |
| CVE-2026-50342 | Medium | 0.3% | 8.8 | Improper access control in Windows MIDI Service Module allows an authorized atta… | |
| CVE-2026-50343 | Medium | 0.3% | 7.8 | Improper privilege management in Microsoft Install Service allows an authorized … | |
| CVE-2026-50344 | Medium | 0.3% | 7.8 | Improper authorization in Windows OLE allows an authorized attacker to elevate p… | |
| CVE-2026-50346 | Medium | 0.3% | 7.8 | Improper authorization in RPC Runtime allows an authorized attacker to elevate p… | |
| CVE-2026-50351 | Medium | 0.3% | 7.8 | Improper access control in Windows Audio Compression Manager (ACM) allows an aut… | |
| CVE-2026-50373 | Medium | 0.3% | 7.8 | Improper access control in Microsoft Windows Search Component allows an authoriz… | |
| CVE-2026-50391 | Medium | 0.3% | 7.8 | Improper privilege management in Windows Group Policy allows an authorized attac… | |
| CVE-2026-50405 | Medium | 0.3% | 7.8 | Insufficient granularity of access control in Windows Filtering Platform (WFP) a… | |
| CVE-2026-50423 | Medium | 0.3% | 7.8 | Improper access control in Windows Kernel allows an authorized attacker to eleva… | |
| CVE-2026-50465 | Medium | 0.3% | 7.1 | Improper access control in Microsoft Windows DNS allows an authorized attacker t… | |
| CVE-2026-55001 | Medium | 0.3% | 7.8 | Improper certificate validation in Windows Active Directory allows an authorized… | |
| CVE-2026-55006 | Medium | 0.3% | 7.8 | Insufficient granularity of access control in Microsoft Exchange Server allows a… | |
| CVE-2026-55014 | Medium | 0.3% | 7.8 | Improper access control in Windows Remote Help Defense allows an authorized atta… | |
| CVE-2026-57088 | Medium | 0.3% | 7.8 | Improper access control in Extensible Storage Engine (ESENT) allows an authorize… | |
| CVE-2026-57107 | Medium | 0.3% | 7.8 | Improper authentication in Windows Admin Center allows an authorized attacker to… | |
| CVE-2026-58540 | Medium | 0.3% | 7.8 | Improper authorization in Windows Installer allows an authorized attacker to ele… | |
| CVE-2026-1220 | Medium | 0.3% | 7.5 | Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to … | |
| CVE-2026-20808 | Medium | 0.3% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20814 | Medium | 0.3% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20815 | Medium | 0.3% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20836 | Medium | 0.3% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20858 | Medium | 0.3% | 7.8 | Use after free in Windows Management Services allows an authorized attacker to e… | |
| CVE-2026-20861 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20866 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20867 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20869 | Medium | 0.3% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20873 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20874 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-47918 | Medium | 0.3% | 7.8 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-47919 | Medium | 0.3% | 7.8 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-7350 | Medium | 0.3% | 8.3 | Use after free in WebMIDI in Google Chrome prior to 147.0.7727.138 allowed a rem… | |
| CVE-2026-7352 | Medium | 0.3% | 8.3 | Use after free in Media in Google Chrome on Android prior to 147.0.7727.138 allo… | |
| CVE-2026-7357 | Medium | 0.3% | 7.5 | Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote … | |
| CVE-2026-50650 | Medium | 0.3% | 7.8 | Improper control of generation of code ('code injection') in .NET Framework allo… | |
| CVE-2026-58650 | Medium | 0.3% | 7.8 | Authorization bypass through user-controlled key in Visual Studio Code allows an… | |
| CVE-2026-66305 | Medium | 0.3% | 7.1 | Use of client-side authentication in Skype for Business allows an authorized att… | |
| CVE-2026-69278 | Medium | 0.3% | 7.8 | Incorrect authorization in Visual Studio Code allows an unauthorized attacker to… | |
| CVE-2026-83939 | Medium | 0.3% | 8.2 | Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized… | |
| CVE-2026-9976 | Medium | 0.3% | 8.8 | Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 all… | |
| CVE-2026-9995 | Medium | 0.3% | 8.8 | Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-48290 | Medium | 0.3% | 8.2 | CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vuln… | |
| CVE-2026-62834 | Medium | 0.3% | 9.3 | Improper verification of cryptographic signature in Azure Data Factory allows an… | |
| CVE-2026-70354 | Medium | 0.3% | 7.8 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code loca… | |
| CVE-2026-48275 | Medium | 0.3% | 8.6 | Illustrator is affected by an Untrusted Search Path vulnerability that could res… | |
| CVE-2026-48340 | Medium | 0.3% | 7.8 | Bridge is affected by an Untrusted Pointer Dereference vulnerability that could … |