microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2022-41090 | Low | 1.0% | 5.9 | Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | |
| CVE-2026-59138 | Low | 1.0% | 6.5 | Null pointer dereference in Microsoft Remote Registry Service allows an authoriz… | |
| CVE-2026-61345 | Low | 1.0% | 6.5 | Null pointer dereference in Microsoft Remote Registry Service allows an authoriz… | |
| CVE-2026-70019 | Low | 1.0% | 6.5 | Windows hard link in Windows Compressed Folder allows an unauthorized attacker t… | |
| CVE-2023-36877 | Low | 1.0% | 4.5 | Azure Apache Oozie Spoofing Vulnerability | |
| CVE-2023-36881 | Low | 1.0% | 4.5 | Azure Apache Ambari Spoofing Vulnerability | |
| CVE-2024-20684 | Low | 1.0% | 6.5 | Windows Hyper-V Denial of Service Vulnerability | |
| CVE-2020-1071 | Low | 1.0% | 6.8 | An elevation of privilege vulnerability exists when Windows improperly handles e… | |
| CVE-2021-36950 | Low | 1.0% | 5.4 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| CVE-2021-36946 | Low | 1.0% | 5.4 | Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | |
| CVE-2023-38188 | Low | 1.0% | 4.5 | Azure Apache Hadoop Spoofing Vulnerability | |
| CVE-2024-43496 | Low | 1.0% | 6.5 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| CVE-2026-50468 | Low | 1.0% | 6.5 | Buffer over-read in SQL Server allows an authorized attacker to disclose informa… | |
| CVE-2026-54116 | Low | 1.0% | 6.5 | Access of resource using incompatible type ('type confusion') in SQL Server allo… | |
| CVE-2026-57982 | Low | 1.0% | 6.5 | Use of uninitialized resource in Windows RDP allows an authorized attacker to di… | |
| CVE-2026-34401 | Low | 1.0% | 6.5 | XML Notepad is a Windows program that provides a simple intuitive User Interface… | |
| CVE-2026-78523 | Low | 1.0% | 5.9 | Use after free in Windows DNS allows an unauthorized attacker to deny service ov… | |
| CVE-2021-33760 | Low | 1.0% | 5.5 | Media Foundation Information Disclosure Vulnerability | |
| CVE-2024-21374 | Low | 1.0% | 5.0 | Microsoft Teams for Android Information Disclosure Vulnerability | |
| CVE-2023-35394 | Low | 1.0% | 4.6 | Azure HDInsight Jupyter Notebook Spoofing Vulnerability | |
| CVE-2026-72977 | Low | 1.0% | 6.5 | Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacke… | |
| CVE-2023-36908 | Low | 1.0% | 6.5 | Windows Hyper-V Information Disclosure Vulnerability | |
| CVE-2026-69723 | Low | 1.0% | 5.7 | Exposure of sensitive system information to an unauthorized control sphere in Wi… | |
| CVE-2021-34491 | Low | 1.0% | 5.5 | Win32k Information Disclosure Vulnerability | |
| CVE-2021-26884 | Low | 1.0% | 5.5 | Windows Media Photo Codec Information Disclosure Vulnerability | |
| CVE-2021-26869 | Low | 1.0% | 5.5 | Windows ActiveX Installer Service Information Disclosure Vulnerability | |
| CVE-2021-24107 | Low | 1.0% | 5.5 | Windows Event Tracing Information Disclosure Vulnerability | |
| CVE-2026-50432 | Low | 1.0% | 5.3 | Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized … | |
| CVE-2026-69636 | Low | 1.0% | 6.5 | Improper neutralization of special elements used in an sql command ('sql injecti… | |
| CVE-2026-69409 | Low | 1.0% | 6.5 | Execution with unnecessary privileges in Microsoft Office SharePoint allows an a… | |
| CVE-2026-67390 | Low | 1.0% | 6.5 | Buffer over-read in SQL Server allows an authorized attacker to disclose informa… | |
| CVE-2026-67383 | Low | 1.0% | 6.5 | Generation of error message containing sensitive information in SQL Server allow… | |
| CVE-2024-21341 | Low | 1.0% | 6.8 | Windows Kernel Remote Code Execution Vulnerability | |
| CVE-2021-42280 | Low | 0.9% | 5.5 | Windows Feedback Hub Elevation of Privilege Vulnerability | |
| CVE-2026-62702 | Low | 0.9% | 6.8 | Null pointer dereference in Windows Graphics Kernel allows an unauthorized attac… | |
| CVE-2021-34509 | Low | 0.9% | 5.5 | Storage Spaces Controller Information Disclosure Vulnerability | |
| CVE-2026-48560 | Low | 0.9% | 5.4 | Deserialization of untrusted data in Microsoft Office SharePoint allows an autho… | |
| CVE-2021-36928 | Low | 0.9% | 6.0 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | |
| CVE-2024-38234 | Low | 0.9% | 6.5 | Windows Networking Denial of Service Vulnerability | |
| CVE-2022-41103 | Low | 0.9% | 5.5 | Microsoft Word Information Disclosure Vulnerability | |
| CVE-2026-20927 | Low | 0.9% | 5.3 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50445 | Low | 0.9% | 6.5 | Buffer over-read in Windows RDP allows an unauthorized attacker to disclose info… | |
| CVE-2026-50497 | Low | 0.9% | 6.5 | Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attac… | |
| CVE-2026-50376 | Low | 0.9% | 6.5 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to … | |
| CVE-2026-50504 | Low | 0.9% | 6.5 | Buffer over-read in Remote Desktop Client allows an unauthorized attacker to dis… | |
| CVE-2026-50519 | Low | 0.9% | 6.5 | Initialization of a resource with an insecure default in GitHub Copilot and Visu… | |
| CVE-2026-55003 | Low | 0.9% | 6.5 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to … | |
| CVE-2026-54126 | Low | 0.9% | 6.5 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose in… | |
| CVE-2026-57979 | Low | 0.9% | 6.5 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose in… | |
| CVE-2026-58546 | Low | 0.9% | 6.5 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to … |