microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-34473 | Act now | 100.0% | 9.1 | ● | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2025-53770 | Act now | 100.0% | 9.8 | ● | Deserialization of untrusted data in on-premises Microsoft SharePoint Server all… |
| CVE-2021-26855 | Act now | 100.0% | 9.1 | ● | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-34523 | Act now | 100.0% | 9.0 | ● | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2021-38647 | Act now | 99.9% | 9.8 | ● | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability |
| CVE-2021-27065 | Act now | 99.9% | 7.8 | ● | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2020-0796 | Act now | 99.8% | 10.0 | ● | A remote code execution vulnerability exists in the way that the Microsoft Serve… |
| CVE-2021-34527 | Act now | 99.8% | 8.8 | ● | A remote code execution vulnerability exists when the Windows Print Spooler serv… |
| CVE-2017-12615 | Act now | 99.6% | 8.1 | ● | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.… |
| CVE-2022-30190 | Act now | 99.2% | 7.8 | ● | A remote code execution vulnerability exists when MSDT is called using the URL p… |
| CVE-2017-0144 | Act now | 99.2% | 8.8 | ● | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 … |
| CVE-2025-49706 | Act now | 99.1% | 6.5 | ● | Improper authentication in Microsoft Office SharePoint allows an unauthorized at… |
| CVE-2020-0618 | Act now | 99.0% | 8.8 | ● | A remote code execution vulnerability exists in Microsoft SQL Server Reporting S… |
| CVE-2023-36884 | Act now | 98.9% | 7.5 | ● | Windows Search Remote Code Execution Vulnerability |
| CVE-2021-33766 | Act now | 98.1% | 7.3 | ● | Microsoft Exchange Server Information Disclosure Vulnerability |
| CVE-2021-40444 | Act now | 97.5% | 8.8 | ● | Microsoft is investigating reports of a remote code execution vulnerability in M… |
| CVE-2021-26857 | Act now | 95.8% | 7.8 | ● | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2024-21412 | Act now | 95.4% | 8.1 | ● | Internet Shortcut Files Security Feature Bypass Vulnerability |
| CVE-2024-21413 | Act now | 94.7% | 9.8 | ● | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2025-8088 | Act now | 94.1% | 8.8 | ● | A path traversal vulnerability affecting the Windows version of WinRAR allows th… |
| CVE-2021-26858 | Act now | 93.7% | 7.8 | ● | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-42321 | Act now | 91.7% | 8.8 | ● | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2017-0145 | Act now | 89.9% | 8.8 | ● | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 … |
| CVE-2018-15982 | Act now | 89.1% | 7.8 | ● | Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a … |
| CVE-2018-8174 | Act now | 88.3% | 7.5 | ● | A remote code execution vulnerability exists in the way that the VBScript engine… |
| CVE-2021-1675 | Act now | 86.1% | 7.8 | ● | Windows Print Spooler Remote Code Execution Vulnerability |
| CVE-2026-50522 | Act now | 85.4% | 9.8 | ● | Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut… |
| CVE-2021-20021 | Act now | 83.4% | 9.8 | ● | A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attac… |
| CVE-2019-0752 | Act now | 81.6% | 7.5 | ● | A remote code execution vulnerability exists in the way that the scripting engin… |
| CVE-2013-0074 | Act now | 81.0% | 7.8 | ● | Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not pr… |
| CVE-2016-7255 | Act now | 81.0% | 7.8 | ● | The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 … |
| CVE-2021-26411 | Act now | 80.8% | 8.8 | ● | Internet Explorer Memory Corruption Vulnerability |
| CVE-2021-1732 | Act now | 78.4% | 7.8 | ● | Windows Win32k Elevation of Privilege Vulnerability |
| CVE-2022-41080 | Act now | 77.3% | 8.8 | ● | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2021-42287 | Act now | 77.2% | 7.5 | ● | Active Directory Domain Services Elevation of Privilege Vulnerability |
| CVE-2026-45659 | Act now | 76.1% | 8.8 | ● | Deserialization of untrusted data in Microsoft Office SharePoint allows an autho… |
| CVE-2019-1458 | Act now | 74.3% | 7.8 | ● | An elevation of privilege vulnerability exists in Windows when the Win32k compon… |
| CVE-2018-8120 | Act now | 73.4% | 7.0 | ● | An elevation of privilege vulnerability exists in Windows when the Win32k compon… |
| CVE-2021-42278 | Act now | 73.3% | 7.5 | ● | Active Directory Domain Services Elevation of Privilege Vulnerability |
| CVE-2026-33824 | Act now | 72.7% | 9.8 | ● | Double free in Windows IKE Extension allows an unauthorized attacker to execute … |
| CVE-2018-8453 | Act now | 70.0% | 7.8 | ● | An elevation of privilege vulnerability exists in Windows when the Win32k compon… |
| CVE-2016-0034 | Act now | 69.4% | 8.8 | ● | Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during de… |
| CVE-2024-30088 | Act now | 68.2% | 7.0 | ● | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2021-36934 | Act now | 67.3% | 7.8 | ● | An elevation of privilege vulnerability exists because of overly permissive Acce… |
| CVE-2021-36942 | Act now | 66.0% | 7.5 | ● | Windows LSA Spoofing Vulnerability |
| CVE-2026-32202 | Act now | 63.7% | 4.3 | ● | Protection mechanism failure in Windows Shell allows an unauthorized attacker to… |
| CVE-2026-45498 | Act now | 63.1% | 4.0 | ● | Microsoft Defender Denial of Service Vulnerability |
| CVE-2023-21529 | Act now | 62.1% | 8.8 | ● | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2024-21338 | Act now | 59.8% | 7.8 | ● | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2022-21882 | Act now | 59.2% | 7.0 | ● | Win32k Elevation of Privilege Vulnerability |
Page 1 of 75
Next →