microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-70329 | Medium | 0.7% | 8.8 | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorize… | |
| CVE-2021-26860 | Medium | 0.7% | 7.8 | Windows App-V Overlay Filter Elevation of Privilege Vulnerability | |
| CVE-2026-62817 | Medium | 0.7% | 8.8 | Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute co… | |
| CVE-2026-67370 | Medium | 0.7% | 8.8 | Improper neutralization of special elements used in an sql command ('sql injecti… | |
| CVE-2026-13448 | Medium | 0.7% | 8.1 | IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated re… | |
| CVE-2026-14499 | Medium | 0.7% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user… | |
| CVE-2026-56162 | Medium | 0.7% | 10.0 | Improper authentication in Azure SQL Database allows an unauthorized attacker to… | |
| CVE-2026-57089 | Medium | 0.7% | 7.5 | Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allow… | |
| CVE-2026-62790 | Medium | 0.7% | 8.8 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker t… | |
| CVE-2026-69514 | Medium | 0.7% | 7.5 | Heap-based buffer overflow in Windows Remote Desktop Services allows an authoriz… | |
| CVE-2026-69599 | Medium | 0.7% | 7.5 | Use after free in Windows Remote Desktop Services allows an authorized attacker … | |
| CVE-2026-50685 | Medium | 0.7% | 7.5 | Double free in Windows DHCP Server allows an authorized attacker to execute code… | |
| CVE-2026-47294 | Medium | 0.7% | 8.0 | Improper neutralization of special elements used in an os command ('os command i… | |
| CVE-2026-62823 | Medium | 0.7% | 8.8 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacke… | |
| CVE-2026-56171 | Medium | 0.7% | 7.1 | Exposure of private personal information to an unauthorized actor in Windows RDP… | |
| CVE-2023-23378 | Medium | 0.7% | 7.8 | Print 3D Remote Code Execution Vulnerability | |
| CVE-2023-23390 | Medium | 0.7% | 7.8 | 3D Builder Remote Code Execution Vulnerability | |
| CVE-2026-50502 | Medium | 0.7% | 8.0 | Insufficient granularity of access control in Windows Event Logging Service allo… | |
| CVE-2026-62913 | Medium | 0.7% | 8.8 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized att… | |
| CVE-2026-69813 | Medium | 0.7% | 8.1 | Use after free in Windows DNS allows an unauthorized attacker to execute code ov… | |
| CVE-2023-23377 | Medium | 0.7% | 7.8 | 3D Builder Remote Code Execution Vulnerability | |
| CVE-2026-81376 | Medium | 0.7% | 9.6 | Incomplete comparison with missing factors in Visual Studio Code allows an unaut… | |
| CVE-2021-33743 | Medium | 0.6% | 7.8 | Windows Projected File System Elevation of Privilege Vulnerability | |
| CVE-2021-33759 | Medium | 0.6% | 7.8 | Windows Desktop Bridge Elevation of Privilege Vulnerability | |
| CVE-2021-33784 | Medium | 0.6% | 7.8 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | |
| CVE-2022-41096 | Medium | 0.6% | 7.8 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | |
| CVE-2023-21802 | Medium | 0.6% | 7.8 | Windows Media Remote Code Execution Vulnerability | |
| CVE-2026-42974 | Medium | 0.6% | 8.1 | Integer overflow or wraparound in Windows Performance Monitor allows an unauthor… | |
| CVE-2026-42981 | Medium | 0.6% | 8.1 | Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an … | |
| CVE-2024-21315 | Medium | 0.6% | 7.8 | Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability | |
| CVE-2021-33773 | Medium | 0.6% | 7.8 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | |
| CVE-2021-34445 | Medium | 0.6% | 7.8 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | |
| CVE-2021-34536 | Medium | 0.6% | 7.8 | Windows Storage Spaces Controller Elevation of Privilege Vulnerability | |
| CVE-2026-69852 | Medium | 0.6% | 7.5 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows… | |
| CVE-2026-50524 | Medium | 0.6% | 7.5 | Improper validation of specified type of input in .NET Framework allows an unaut… | |
| CVE-2026-72987 | Medium | 0.6% | 8.1 | Use after free in Windows DNS allows an unauthorized attacker to execute code ov… | |
| CVE-2021-33774 | Medium | 0.6% | 7.0 | Windows Event Tracing Elevation of Privilege Vulnerability | |
| CVE-2026-24304 | Medium | 0.6% | 9.9 | Improper access control in Azure Resource Manager allows an authorized attacker … | |
| CVE-2026-62822 | Medium | 0.6% | 8.8 | Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker t… | |
| CVE-2023-21820 | Medium | 0.6% | 7.4 | Windows Distributed File System (DFS) Remote Code Execution Vulnerability | |
| CVE-2026-66307 | Medium | 0.6% | 7.5 | Integer underflow (wrap or wraparound) in Skype for Business allows an unauthori… | |
| CVE-2026-70332 | Medium | 0.6% | 9.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-84001 | Medium | 0.6% | 7.5 | Out-of-bounds read in Windows Key Distribution Center allows an unauthorized att… | |
| CVE-2026-40371 | Medium | 0.6% | 8.8 | Improper handling of insufficient permissions or privileges in Microsoft Dynamic… | |
| CVE-2026-62870 | Medium | 0.6% | 8.8 | Use after free in Microsoft Office Excel allows an unauthorized attacker to exec… | |
| CVE-2026-34615 | Medium | 0.6% | 9.3 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserializati… | |
| CVE-2026-61363 | Medium | 0.6% | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac… | |
| CVE-2026-62824 | Medium | 0.6% | 8.8 | Stack-based buffer overflow in Remote Desktop Client allows an unauthorized atta… | |
| CVE-2026-65768 | Medium | 0.6% | 8.8 | Improper limitation of a pathname to a restricted directory ('path traversal') i… | |
| CVE-2026-59134 | Medium | 0.6% | 7.5 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac… |