microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-35560 | Medium | 0.3% | 7.4 | Improper certificate validation in the identity provider connection components i… | |
| CVE-2026-44810 | Medium | 0.3% | 8.4 | Improper authentication in Windows Cryptographic Services allows an unauthorized… | |
| CVE-2026-69874 | Medium | 0.3% | 8.2 | Untrusted pointer dereference in Windows ALPC allows an authorized attacker to e… | |
| CVE-2026-8834 | Medium | 0.3% | 8.0 | IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privile… | |
| CVE-2026-11144 | Medium | 0.3% | 8.8 | Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-9940 | Medium | 0.3% | 8.8 | Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a… | |
| CVE-2026-11660 | Medium | 0.3% | 8.3 | Insufficient validation of untrusted input in New Tab Page in Google Chrome prio… | |
| CVE-2026-10890 | Medium | 0.3% | 8.8 | Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attack… | |
| CVE-2026-50512 | Medium | 0.3% | 7.8 | Missing authentication for critical function in Microsoft PC Manager allows an a… | |
| CVE-2026-62799 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows SMB Client allows an authorized attacker t… | |
| CVE-2026-65671 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Remote Access API allows an authorized att… | |
| CVE-2026-65672 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Remote Access API allows an authorized att… | |
| CVE-2026-65774 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Installer allows an authorized attacker to… | |
| CVE-2026-11688 | Medium | 0.3% | 8.8 | Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 all… | |
| CVE-2026-47967 | Medium | 0.3% | 7.8 | Audition is affected by an out-of-bounds write vulnerability that could result i… | |
| CVE-2026-47968 | Medium | 0.3% | 7.8 | Audition is affected by an out-of-bounds write vulnerability that could result i… | |
| CVE-2026-48309 | Medium | 0.3% | 7.8 | Audition is affected by an out-of-bounds write vulnerability that could result i… | |
| CVE-2026-48311 | Medium | 0.3% | 7.8 | Bridge is affected by an out-of-bounds write vulnerability that could result in … | |
| CVE-2026-48335 | Medium | 0.3% | 7.8 | Illustrator is affected by an out-of-bounds write vulnerability that could resul… | |
| CVE-2026-48336 | Medium | 0.3% | 7.8 | Illustrator is affected by an out-of-bounds write vulnerability that could resul… | |
| CVE-2026-48337 | Medium | 0.3% | 7.8 | Illustrator is affected by an out-of-bounds write vulnerability that could resul… | |
| CVE-2026-48341 | Medium | 0.3% | 7.8 | Bridge is affected by an out-of-bounds write vulnerability that could result in … | |
| CVE-2026-48343 | Medium | 0.3% | 7.8 | Bridge is affected by an out-of-bounds write vulnerability that could result in … | |
| CVE-2026-48365 | Medium | 0.3% | 7.8 | Audition is affected by an out-of-bounds write vulnerability that could result i… | |
| CVE-2026-48368 | Medium | 0.3% | 7.8 | Audition is affected by an out-of-bounds write vulnerability that could result i… | |
| CVE-2026-50305 | Medium | 0.3% | 7.8 | Use after free in Microsoft Brokering File System allows an authorized attacker … | |
| CVE-2026-50361 | Medium | 0.3% | 7.8 | Double free in Microsoft Brokering File System allows an authorized attacker to … | |
| CVE-2026-50385 | Medium | 0.3% | 8.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50427 | Medium | 0.3% | 7.8 | Use after free in Content Delivery Manager allows an authorized attacker to elev… | |
| CVE-2026-50457 | Medium | 0.3% | 7.8 | Use after free in Windows Runtime allows an authorized attacker to elevate privi… | |
| CVE-2026-50458 | Medium | 0.3% | 7.8 | Use after free in Microsoft Brokering File System allows an authorized attacker … | |
| CVE-2026-50677 | Medium | 0.3% | 7.8 | Use after free in Windows Media allows an authorized attacker to elevate privile… | |
| CVE-2026-50689 | Medium | 0.3% | 7.8 | Use after free in Windows Clipboard Server allows an authorized attacker to elev… | |
| CVE-2026-54125 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-70585 | Medium | 0.3% | 7.0 | Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorize… | |
| CVE-2026-11052 | Medium | 0.3% | 9.6 | Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed… | |
| CVE-2026-9901 | Medium | 0.3% | 7.5 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-9909 | Medium | 0.3% | 7.5 | Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remo… | |
| CVE-2026-9983 | Medium | 0.3% | 8.8 | Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote… | |
| CVE-2026-62759 | Medium | 0.3% | 7.5 | Authentication bypass by spoofing in Windows Netlogon allows an unauthorized att… | |
| CVE-2026-5874 | Medium | 0.3% | 9.6 | Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a re… | |
| CVE-2026-76191 | Medium | 0.3% | 8.2 | Animate is affected by an Improper Control of Generation of Code ('Code Injectio… | |
| CVE-2026-10007 | Medium | 0.3% | 8.8 | Use after free in SVG in Google Chrome prior to 148.0.7778.216 allowed a remote … | |
| CVE-2026-10015 | Medium | 0.3% | 8.8 | Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-10016 | Medium | 0.3% | 8.8 | Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote … | |
| CVE-2026-11630 | Medium | 0.3% | 8.8 | Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a … | |
| CVE-2026-11634 | Medium | 0.3% | 9.6 | Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 al… | |
| CVE-2026-11638 | Medium | 0.3% | 9.6 | Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a re… | |
| CVE-2026-11664 | Medium | 0.3% | 8.8 | Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a re… | |
| CVE-2026-21280 | Medium | 0.3% | 8.6 | Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Searc… |