← All vendors

microsoft

3,712 known vulnerabilities affecting microsoft products.

Products

windows_server_2019 1452 windows_server_2016 1310 windows_server_2022 1272 windows_server_2025 1131 windows_10_1809 1131 windows_11_24h2 1111 windows_11_25h2 1081 windows_10_22h2 1066 windows_10_21h2 1061 windows_11_26h1 1009 windows 990 windows_10_1607 980 windows_server_2012 977 windows_11_23h2 761 windows_10 343 windows_server_2008 326 365_apps 277 office_2021 225 office_2024 225 office_2019 217 windows_8.1 192 microsoft_365 185 windows_rt_8.1 170 windows_7 169

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-23663 Medium 0.6% 7.5 Improper privilege management in Azure Entra ID allows an unauthorized attacker …
CVE-2026-3087 Medium 0.6% 7.5 If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows pat…
CVE-2021-38667 Medium 0.6% 7.8 Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-38671 Medium 0.6% 7.8 Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2026-47654 Medium 0.6% 7.5 Use after free in Remote Desktop Client allows an unauthorized attacker to execu…
CVE-2026-48563 Medium 0.6% 7.5 Use after free in Remote Desktop Client allows an unauthorized attacker to execu…
CVE-2026-66803 Medium 0.6% 10.0 Improper access control in Azure Cosmos DB allows an unauthorized attacker to ex…
CVE-2026-66321 Medium 0.5% 7.4 Access of resource using incompatible type ('type confusion') in Microsoft Edge …
CVE-2022-41050 Medium 0.5% 7.8 Windows Extensible File Allocation Table Elevation of Privilege Vulnerability
CVE-2026-48397 Medium 0.5% 8.6 Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerabili…
CVE-2021-42285 Medium 0.5% 7.8 Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-62706 Medium 0.5% 8.8 Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized …
CVE-2026-69529 Medium 0.5% 8.8 Heap-based buffer overflow in Microsoft Office Access allows an unauthorized att…
CVE-2026-77486 Medium 0.5% 8.8 Integer overflow or wraparound in SQL Server allows an unauthorized attacker to …
CVE-2026-77907 Medium 0.5% 8.8 Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to e…
CVE-2026-78989 Medium 0.5% 9.6 Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.6…
CVE-2026-79048 Medium 0.5% 8.8 Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.…
CVE-2021-36968 Medium 0.5% 7.8 Windows DNS Elevation of Privilege Vulnerability
CVE-2026-65789 Medium 0.5% 8.1 Use after free in Windows DNS allows an unauthorized attacker to execute code ov…
CVE-2023-38175 Medium 0.5% 7.8 Microsoft Windows Defender Elevation of Privilege Vulnerability
CVE-2026-62820 Medium 0.5% 8.1 Concurrent execution using shared resource with improper synchronization ('race …
CVE-2021-42322 Medium 0.5% 7.8 Visual Studio Code Elevation of Privilege Vulnerability
CVE-2026-42900 Medium 0.5% 8.1 Concurrent execution using shared resource with improper synchronization ('race …
CVE-2026-50365 Medium 0.5% 8.0 Improper authentication in Windows RPC API allows an unauthorized attacker to el…
CVE-2026-50460 Medium 0.5% 8.1 Concurrent execution using shared resource with improper synchronization ('race …
CVE-2026-68782 Medium 0.5% 9.9 Improper neutralization of special elements used in an sql command ('sql injecti…
CVE-2026-66800 Medium 0.5% 8.6 Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized …
CVE-2026-69558 Medium 0.5% 8.6 Authorization bypass through user-controlled key in Microsoft Partner Center all…
CVE-2026-62872 Medium 0.5% 8.8 Incorrect authorization in .NET Framework allows an authorized attacker to eleva…
CVE-2026-9119 Medium 0.5% 8.8 Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allow…
CVE-2026-42975 Medium 0.5% 8.0 Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthoriz…
CVE-2026-33826 Medium 0.5% 8.0 Improper input validation in Windows Active Directory allows an authorized attac…
CVE-2026-40412 Medium 0.5% 10.0 Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows a…
CVE-2026-63508 Medium 0.5% 10.0 Missing authentication for critical function in Microsoft Planetary Computer Pro…
CVE-2022-41101 Medium 0.5% 7.8 Windows Overlay Filter Elevation of Privilege Vulnerability
CVE-2022-41102 Medium 0.5% 7.8 Windows Overlay Filter Elevation of Privilege Vulnerability
CVE-2026-66302 Medium 0.5% 9.8 External control of file name or path in Skype for Business allows an unauthoriz…
CVE-2026-72970 Medium 0.5% 8.3 Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthor…
CVE-2022-41114 Medium 0.5% 7.0 Windows Bind Filter Driver Elevation of Privilege Vulnerability
CVE-2026-62787 Medium 0.5% 7.5 Use after free in Windows DNS allows an authorized attacker to execute code over…
CVE-2026-66820 Medium 0.5% 8.8 Improper neutralization of special elements used in an sql command ('sql injecti…
CVE-2026-68789 Medium 0.5% 9.9 Improper neutralization of special elements used in an sql command ('sql injecti…
CVE-2026-8056 Medium 0.5% 8.8 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override com…
CVE-2026-8635 Medium 0.5% 9.9 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate pri…
CVE-2026-35425 Medium 0.5% 8.0 Improper access control in Azure API Management (APIM) allows an authorized atta…
CVE-2026-62873 Medium 0.5% 9.8 Improper verification of cryptographic signature in Microsoft 365 Admin Center a…
CVE-2026-65796 Medium 0.5% 8.1 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorize…
CVE-2022-37992 Medium 0.5% 7.8 Windows Group Policy Elevation of Privilege Vulnerability
CVE-2026-47300 Medium 0.5% 8.8 Incorrect implementation of authentication algorithm in ASP.NET Core allows an a…
CVE-2026-57969 Medium 0.5% 8.8 Missing authentication for critical function in Azure CycleCloud allows an autho…
← Prev Page 23 of 75 Next →