microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-69273 | Medium | 0.5% | 8.8 | Improper access control in Microsoft Office SharePoint allows an authorized atta… | |
| CVE-2026-69282 | Medium | 0.5% | 8.8 | Improper access control in Microsoft Office SharePoint allows an authorized atta… | |
| CVE-2026-73028 | Medium | 0.5% | 8.8 | Improper access control in SQL Server allows an authorized attacker to elevate p… | |
| CVE-2026-77480 | Medium | 0.5% | 8.8 | Insufficient granularity of access control in SQL Server allows an authorized at… | |
| CVE-2026-77483 | Medium | 0.5% | 8.8 | Weak authentication in SQL Server allows an authorized attacker to elevate privi… | |
| CVE-2026-77487 | Medium | 0.5% | 8.8 | Improper access control in SQL Server allows an authorized attacker to elevate p… | |
| CVE-2021-34455 | Medium | 0.5% | 7.8 | Windows File History Service Elevation of Privilege Vulnerability | |
| CVE-2021-34459 | Medium | 0.5% | 7.8 | Windows AppContainer Elevation Of Privilege Vulnerability | |
| CVE-2021-34461 | Medium | 0.5% | 7.8 | Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerabilit… | |
| CVE-2021-36927 | Medium | 0.5% | 7.8 | Windows Digital TV Tuner device registration application Elevation of Privilege … | |
| CVE-2026-40411 | Medium | 0.5% | 9.9 | Improper input validation in Azure Virtual Network Gateway allows an authorized … | |
| CVE-2026-65811 | Medium | 0.5% | 8.8 | Improper input validation in Power BI allows an authorized attacker to execute c… | |
| CVE-2021-36954 | Medium | 0.5% | 8.8 | Windows Bind Filter Driver Elevation of Privilege Vulnerability | |
| CVE-2021-36964 | Medium | 0.5% | 7.8 | Windows Event Tracing Elevation of Privilege Vulnerability | |
| CVE-2021-36966 | Medium | 0.5% | 7.8 | Windows Subsystem for Linux Elevation of Privilege Vulnerability | |
| CVE-2021-36973 | Medium | 0.5% | 7.8 | Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability | |
| CVE-2021-36974 | Medium | 0.5% | 7.8 | Windows SMB Elevation of Privilege Vulnerability | |
| CVE-2021-38625 | Medium | 0.5% | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2021-38626 | Medium | 0.5% | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | |
| CVE-2021-38628 | Medium | 0.5% | 7.8 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerabili… | |
| CVE-2021-38630 | Medium | 0.5% | 7.8 | Windows Event Tracing Elevation of Privilege Vulnerability | |
| CVE-2021-38638 | Medium | 0.5% | 7.8 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerabili… | |
| CVE-2023-21815 | Medium | 0.5% | 7.8 | Visual Studio Remote Code Execution Vulnerability | |
| CVE-2026-65816 | Medium | 0.5% | 10.0 | Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorize… | |
| CVE-2026-69314 | Medium | 0.5% | 7.1 | Use after free in Windows Device Association Broker service allows an authorized… | |
| CVE-2026-44803 | Medium | 0.5% | 7.8 | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized a… | |
| CVE-2026-44812 | Medium | 0.5% | 7.8 | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized a… | |
| CVE-2026-45583 | Medium | 0.5% | 7.5 | Improper control of generation of code ('code injection') in Microsoft Exchange … | |
| CVE-2026-68835 | Medium | 0.5% | 7.1 | Use after free in Windows Print Spooler Components allows an authorized attacker… | |
| CVE-2026-68893 | Medium | 0.5% | 7.1 | Use after free in Windows Remote Desktop Licensing Service allows an authorized … | |
| CVE-2026-69340 | Medium | 0.5% | 7.1 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elev… | |
| CVE-2026-45599 | Medium | 0.5% | 8.1 | Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized atta… | |
| CVE-2026-45635 | Medium | 0.5% | 8.1 | Access of resource using incompatible type ('type confusion') in Universal Plug … | |
| CVE-2022-41054 | Medium | 0.5% | 7.8 | Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | |
| CVE-2026-62781 | Medium | 0.5% | 8.1 | Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to exe… | |
| CVE-2026-44822 | Medium | 0.5% | 8.2 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2026-50338 | Medium | 0.5% | 8.2 | Improper authentication in Azure Spring Apps allows an authorized attacker to el… | |
| CVE-2022-41095 | Medium | 0.5% | 7.8 | Windows Digital Media Receiver Elevation of Privilege Vulnerability | |
| CVE-2026-62830 | Medium | 0.5% | 9.9 | Missing authorization in Azure SRE Agent allows an authorized attacker to elevat… | |
| CVE-2026-65668 | Medium | 0.5% | 8.8 | Improper access control in Microsoft Purview eDiscovery allows an authorized att… | |
| CVE-2026-34690 | Medium | 0.5% | 7.8 | After Effects is affected by a Stack-based Buffer Overflow vulnerability that co… | |
| CVE-2026-79194 | Medium | 0.5% | 8.1 | Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.… | |
| CVE-2026-65801 | Medium | 0.5% | 10.0 | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauth… | |
| CVE-2026-69539 | Medium | 0.5% | 7.5 | Use after free in Windows Remote Desktop Services allows an authorized attacker … | |
| CVE-2026-50379 | Medium | 0.5% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-56648 | Medium | 0.5% | 7.5 | Time-of-check time-of-use (toctou) race condition in Windows Network File System… | |
| CVE-2026-58531 | Medium | 0.5% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-69804 | Medium | 0.5% | 7.5 | Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint… | |
| CVE-2026-20804 | Medium | 0.5% | 7.7 | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker … | |
| CVE-2026-20852 | Medium | 0.5% | 7.7 | Incorrect privilege assignment in Windows Hello allows an unauthorized attacker … |