microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-63509 | Medium | 0.6% | 9.9 | Relative path traversal in Microsoft Fabric allows an authorized attacker to ele… | |
| CVE-2026-65667 | Medium | 0.6% | 10.0 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elev… | |
| CVE-2026-72928 | Medium | 0.6% | 7.5 | Use after free in Windows DNS allows an authorized attacker to execute code over… | |
| CVE-2026-55002 | Medium | 0.6% | 8.8 | External control of file name or path in SQL Server allows an authorized attacke… | |
| CVE-2026-67373 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execut… | |
| CVE-2026-67379 | Medium | 0.6% | 8.5 | Stack-based buffer overflow in SQL Server allows an authorized attacker to execu… | |
| CVE-2026-67384 | Medium | 0.6% | 8.8 | Integer overflow or wraparound in SQL Server allows an authorized attacker to ex… | |
| CVE-2026-73012 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Windows Management Services allows an authorized a… | |
| CVE-2026-77481 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execut… | |
| CVE-2024-21364 | Medium | 0.6% | 9.3 | Microsoft Azure Site Recovery Elevation of Privilege Vulnerability | |
| CVE-2024-21354 | Medium | 0.6% | 7.8 | Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability | |
| CVE-2026-27303 | Medium | 0.6% | 9.6 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserializati… | |
| CVE-2026-57098 | Medium | 0.6% | 7.5 | Improper verification of cryptographic signature in Windows RDP Client allows an… | |
| CVE-2021-34487 | Medium | 0.6% | 7.0 | Windows Event Tracing Elevation of Privilege Vulnerability | |
| CVE-2026-5858 | Medium | 0.6% | 8.8 | Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a … | |
| CVE-2026-59117 | Medium | 0.6% | 7.5 | Integer overflow or wraparound in Windows Terminal allows an unauthorized attack… | |
| CVE-2026-69607 | Medium | 0.6% | 7.5 | Use after free in Windows Deployment Services allows an unauthorized attacker to… | |
| CVE-2026-33414 | Medium | 0.6% | 7.8 | Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.… | |
| CVE-2026-56188 | Medium | 0.6% | 9.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62795 | Medium | 0.6% | 8.8 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an… | |
| CVE-2026-70336 | Medium | 0.6% | 8.8 | Improper control of generation of code ('code injection') in Visual Studio Code … | |
| CVE-2026-80080 | Medium | 0.6% | 8.8 | Double free in Microsoft Office Word allows an unauthorized attacker to execute … | |
| CVE-2024-38252 | Medium | 0.6% | 7.8 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | |
| CVE-2024-38253 | Medium | 0.6% | 7.8 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | |
| CVE-2026-50525 | Medium | 0.6% | 7.5 | Allocation of resources without limits or throttling in .NET allows an unauthori… | |
| CVE-2026-68823 | Medium | 0.6% | 9.1 | Exposed dangerous method or function in Azure Confidential Ledger allows an auth… | |
| CVE-2026-78519 | Medium | 0.6% | 8.8 | Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized… | |
| CVE-2022-41123 | Medium | 0.6% | 7.8 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| CVE-2026-70340 | Medium | 0.6% | 8.1 | Missing authorization in Azure CycleCloud allows an authorized attacker to eleva… | |
| CVE-2026-47653 | Medium | 0.6% | 8.8 | Use after free in Remote Desktop Client allows an unauthorized attacker to execu… | |
| CVE-2021-33761 | Medium | 0.6% | 7.8 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | |
| CVE-2026-54984 | Medium | 0.6% | 7.8 | Heap-based buffer overflow in Windows Imaging Component allows an unauthorized a… | |
| CVE-2026-65791 | Medium | 0.6% | 9.8 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorize… | |
| CVE-2023-21809 | Medium | 0.6% | 7.8 | Microsoft Defender for Endpoint Security Feature Bypass Vulnerability | |
| CVE-2026-62916 | Medium | 0.6% | 9.1 | Authentication bypass using an alternate path or channel in Microsoft Entra ID a… | |
| CVE-2021-26429 | Medium | 0.6% | 7.7 | Azure Sphere Elevation of Privilege Vulnerability | |
| CVE-2026-26135 | Medium | 0.6% | 9.6 | Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (… | |
| CVE-2026-81952 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attac… | |
| CVE-2026-83992 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Windows Imaging Component allows an unauthorized a… | |
| CVE-2024-38016 | Medium | 0.6% | 7.8 | Microsoft Office Visio Remote Code Execution Vulnerability | |
| CVE-2026-68846 | Medium | 0.6% | 7.1 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-69366 | Medium | 0.6% | 7.1 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-77901 | Medium | 0.6% | 8.8 | Null pointer dereference in Microsoft Office Word allows an unauthorized attacke… | |
| CVE-2026-78504 | Medium | 0.6% | 8.8 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized atta… | |
| CVE-2026-78507 | Medium | 0.6% | 8.8 | Use after free in Microsoft Office Word allows an unauthorized attacker to execu… | |
| CVE-2026-78514 | Medium | 0.6% | 8.8 | Use after free in Microsoft Office Word allows an unauthorized attacker to execu… | |
| CVE-2026-78517 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attac… | |
| CVE-2026-78521 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attac… | |
| CVE-2026-78526 | Medium | 0.6% | 8.8 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attac… | |
| CVE-2026-48448 | Medium | 0.6% | 8.6 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia… |