microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-23663 | Medium | 0.6% | 7.5 | Improper privilege management in Azure Entra ID allows an unauthorized attacker … | |
| CVE-2026-3087 | Medium | 0.6% | 7.5 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows pat… | |
| CVE-2021-38667 | Medium | 0.6% | 7.8 | Windows Print Spooler Elevation of Privilege Vulnerability | |
| CVE-2021-38671 | Medium | 0.6% | 7.8 | Windows Print Spooler Elevation of Privilege Vulnerability | |
| CVE-2026-47654 | Medium | 0.6% | 7.5 | Use after free in Remote Desktop Client allows an unauthorized attacker to execu… | |
| CVE-2026-48563 | Medium | 0.6% | 7.5 | Use after free in Remote Desktop Client allows an unauthorized attacker to execu… | |
| CVE-2026-66803 | Medium | 0.6% | 10.0 | Improper access control in Azure Cosmos DB allows an unauthorized attacker to ex… | |
| CVE-2026-66321 | Medium | 0.5% | 7.4 | Access of resource using incompatible type ('type confusion') in Microsoft Edge … | |
| CVE-2022-41050 | Medium | 0.5% | 7.8 | Windows Extensible File Allocation Table Elevation of Privilege Vulnerability | |
| CVE-2026-48397 | Medium | 0.5% | 8.6 | Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerabili… | |
| CVE-2021-42285 | Medium | 0.5% | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2026-62706 | Medium | 0.5% | 8.8 | Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized … | |
| CVE-2026-69529 | Medium | 0.5% | 8.8 | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized att… | |
| CVE-2026-77486 | Medium | 0.5% | 8.8 | Integer overflow or wraparound in SQL Server allows an unauthorized attacker to … | |
| CVE-2026-77907 | Medium | 0.5% | 8.8 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to e… | |
| CVE-2026-78989 | Medium | 0.5% | 9.6 | Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.6… | |
| CVE-2026-79048 | Medium | 0.5% | 8.8 | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.… | |
| CVE-2021-36968 | Medium | 0.5% | 7.8 | Windows DNS Elevation of Privilege Vulnerability | |
| CVE-2026-65789 | Medium | 0.5% | 8.1 | Use after free in Windows DNS allows an unauthorized attacker to execute code ov… | |
| CVE-2023-38175 | Medium | 0.5% | 7.8 | Microsoft Windows Defender Elevation of Privilege Vulnerability | |
| CVE-2026-62820 | Medium | 0.5% | 8.1 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2021-42322 | Medium | 0.5% | 7.8 | Visual Studio Code Elevation of Privilege Vulnerability | |
| CVE-2026-42900 | Medium | 0.5% | 8.1 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50365 | Medium | 0.5% | 8.0 | Improper authentication in Windows RPC API allows an unauthorized attacker to el… | |
| CVE-2026-50460 | Medium | 0.5% | 8.1 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-68782 | Medium | 0.5% | 9.9 | Improper neutralization of special elements used in an sql command ('sql injecti… | |
| CVE-2026-66800 | Medium | 0.5% | 8.6 | Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized … | |
| CVE-2026-69558 | Medium | 0.5% | 8.6 | Authorization bypass through user-controlled key in Microsoft Partner Center all… | |
| CVE-2026-62872 | Medium | 0.5% | 8.8 | Incorrect authorization in .NET Framework allows an authorized attacker to eleva… | |
| CVE-2026-9119 | Medium | 0.5% | 8.8 | Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allow… | |
| CVE-2026-42975 | Medium | 0.5% | 8.0 | Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthoriz… | |
| CVE-2026-33826 | Medium | 0.5% | 8.0 | Improper input validation in Windows Active Directory allows an authorized attac… | |
| CVE-2026-40412 | Medium | 0.5% | 10.0 | Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows a… | |
| CVE-2026-63508 | Medium | 0.5% | 10.0 | Missing authentication for critical function in Microsoft Planetary Computer Pro… | |
| CVE-2022-41101 | Medium | 0.5% | 7.8 | Windows Overlay Filter Elevation of Privilege Vulnerability | |
| CVE-2022-41102 | Medium | 0.5% | 7.8 | Windows Overlay Filter Elevation of Privilege Vulnerability | |
| CVE-2026-66302 | Medium | 0.5% | 9.8 | External control of file name or path in Skype for Business allows an unauthoriz… | |
| CVE-2026-72970 | Medium | 0.5% | 8.3 | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthor… | |
| CVE-2022-41114 | Medium | 0.5% | 7.0 | Windows Bind Filter Driver Elevation of Privilege Vulnerability | |
| CVE-2026-62787 | Medium | 0.5% | 7.5 | Use after free in Windows DNS allows an authorized attacker to execute code over… | |
| CVE-2026-66820 | Medium | 0.5% | 8.8 | Improper neutralization of special elements used in an sql command ('sql injecti… | |
| CVE-2026-68789 | Medium | 0.5% | 9.9 | Improper neutralization of special elements used in an sql command ('sql injecti… | |
| CVE-2026-8056 | Medium | 0.5% | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override com… | |
| CVE-2026-8635 | Medium | 0.5% | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate pri… | |
| CVE-2026-35425 | Medium | 0.5% | 8.0 | Improper access control in Azure API Management (APIM) allows an authorized atta… | |
| CVE-2026-62873 | Medium | 0.5% | 9.8 | Improper verification of cryptographic signature in Microsoft 365 Admin Center a… | |
| CVE-2026-65796 | Medium | 0.5% | 8.1 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorize… | |
| CVE-2022-37992 | Medium | 0.5% | 7.8 | Windows Group Policy Elevation of Privilege Vulnerability | |
| CVE-2026-47300 | Medium | 0.5% | 8.8 | Incorrect implementation of authentication algorithm in ASP.NET Core allows an a… | |
| CVE-2026-57969 | Medium | 0.5% | 8.8 | Missing authentication for critical function in Azure CycleCloud allows an autho… |