microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-62776 | Medium | 0.3% | 7.8 | Improper link resolution before file access ('link following') in Windows DHCP S… | |
| CVE-2026-11629 | Medium | 0.3% | 8.8 | Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remot… | |
| CVE-2026-68821 | Medium | 0.3% | 7.3 | Improper privilege management in Windows Package Manager allows an authorized at… | |
| CVE-2026-62890 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to exec… | |
| CVE-2026-66799 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to… | |
| CVE-2026-48578 | Medium | 0.3% | 7.9 | Improper access control in Windows Secure Boot allows an authorized attacker to … | |
| CVE-2026-10933 | Medium | 0.3% | 8.3 | Use after free in Audio in Google Chrome on Windows prior to 149.0.7827.53 allow… | |
| CVE-2026-27310 | Medium | 0.3% | 7.8 | Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer O… | |
| CVE-2026-44802 | Medium | 0.3% | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elev… | |
| CVE-2026-44804 | Medium | 0.3% | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elev… | |
| CVE-2026-44807 | Medium | 0.3% | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elev… | |
| CVE-2026-44808 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows DWM Core Library allows an authorized atta… | |
| CVE-2026-44809 | Medium | 0.3% | 7.8 | Use after free in Windows Common Log File System Driver allows an authorized att… | |
| CVE-2026-44811 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows DWM Core Library allows an authorized atta… | |
| CVE-2026-44813 | Medium | 0.3% | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elev… | |
| CVE-2026-48583 | Medium | 0.3% | 7.8 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-65810 | Medium | 0.3% | 7.8 | Relative path traversal in .NET Framework allows an unauthorized attacker to ele… | |
| CVE-2026-77101 | Medium | 0.3% | 7.5 | CommServe contained a stack-based buffer overflow issue affecting service availa… | |
| CVE-2026-77102 | Medium | 0.3% | 7.5 | CommServe contained a heap-based buffer overflow issue affecting service availab… | |
| CVE-2026-87644 | Medium | 0.3% | 8.3 | Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8… | |
| CVE-2026-11153 | Medium | 0.3% | 9.1 | Side-channel information leakage in Forms in Google Chrome prior to 149.0.7827.5… | |
| CVE-2026-11242 | Medium | 0.3% | 7.5 | Insufficient validation of untrusted input in Plugins in Google Chrome prior to … | |
| CVE-2026-11255 | Medium | 0.3% | 7.5 | Insufficient validation of untrusted input in Storage Access API in Google Chrom… | |
| CVE-2026-11632 | Medium | 0.3% | 7.5 | Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a re… | |
| CVE-2026-48571 | Medium | 0.3% | 7.0 | Use after free in Windows App Installer allows an authorized attacker to elevate… | |
| CVE-2026-49162 | Medium | 0.3% | 7.0 | Use after free in Microsoft Brokering File System allows an authorized attacker … | |
| CVE-2026-50296 | Medium | 0.3% | 7.0 | Use after free in Graphics Kernel allows an authorized attacker to elevate privi… | |
| CVE-2026-50323 | Medium | 0.3% | 7.0 | Use after free in Windows Runtime allows an authorized attacker to elevate privi… | |
| CVE-2026-50372 | Medium | 0.3% | 7.0 | Buffer over-read in Windows Redirected Drive Buffering allows an authorized atta… | |
| CVE-2026-50392 | Medium | 0.3% | 7.0 | Use after free in Windows Secure Kernel Mode allows an authorized attacker to el… | |
| CVE-2026-50397 | Medium | 0.3% | 7.0 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-50410 | Medium | 0.3% | 7.0 | Use after free in Windows Runtime allows an authorized attacker to elevate privi… | |
| CVE-2026-50449 | Medium | 0.3% | 7.0 | Use after free in Windows Runtime allows an authorized attacker to elevate privi… | |
| CVE-2026-56173 | Medium | 0.3% | 7.0 | Use after free in Windows WebView allows an authorized attacker to elevate privi… | |
| CVE-2026-56183 | Medium | 0.3% | 7.0 | Use after free in Windows MIDI Service Module allows an authorized attacker to e… | |
| CVE-2026-58544 | Medium | 0.3% | 7.0 | Use after free in Windows Management Services allows an authorized attacker to e… | |
| CVE-2026-58619 | Medium | 0.3% | 7.0 | Use after free in Windows Sensor Data Service allows an authorized attacker to e… | |
| CVE-2026-58629 | Medium | 0.3% | 7.0 | Use after free in Windows DirectX allows an authorized attacker to elevate privi… | |
| CVE-2026-58637 | Medium | 0.3% | 7.0 | Use after free in Windows Client-Side Caching (CSC) Service allows an authorized… | |
| CVE-2026-68884 | Medium | 0.3% | 7.0 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to el… | |
| CVE-2026-69310 | Medium | 0.3% | 7.0 | Use after free in Windows DNS allows an authorized attacker to elevate privilege… | |
| CVE-2026-69379 | Medium | 0.3% | 7.0 | Improper link resolution before file access ('link following') in Windows NTFS a… | |
| CVE-2026-69473 | Medium | 0.3% | 7.0 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-71340 | Medium | 0.3% | 7.0 | Use after free in Windows File History Service allows an authorized attacker to … | |
| CVE-2026-10888 | Medium | 0.3% | 8.8 | Use after free in Cast Streaming in Google Chrome prior to 149.0.7827.53 allowed… | |
| CVE-2026-11648 | Medium | 0.3% | 8.8 | Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.103… | |
| CVE-2026-44818 | Medium | 0.3% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-11646 | Medium | 0.3% | 8.8 | Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 allow… | |
| CVE-2026-48346 | Medium | 0.3% | 7.9 | Animate is affected by an Untrusted Search Path vulnerability that could result … | |
| CVE-2026-70573 | Medium | 0.3% | 7.0 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… |