microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-81953 | Medium | 0.4% | 7.8 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized att… | |
| CVE-2026-81959 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… | |
| CVE-2026-10910 | Medium | 0.4% | 8.8 | Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote at… | |
| CVE-2026-84003 | Medium | 0.4% | 7.4 | Authentication bypass by capture-replay in Microsoft Authentication Library (MSA… | |
| CVE-2026-7337 | Medium | 0.4% | 8.8 | Type Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote a… | |
| CVE-2023-21804 | Medium | 0.4% | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability | |
| CVE-2026-7336 | Medium | 0.4% | 8.8 | Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remo… | |
| CVE-2026-41134 | Medium | 0.4% | 7.8 | Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 a… | |
| CVE-2026-68798 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… | |
| CVE-2026-70335 | Medium | 0.4% | 7.8 | Improper neutralization of special elements used in an os command ('os command i… | |
| CVE-2026-41090 | Medium | 0.4% | 9.3 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2026-10941 | Medium | 0.4% | 8.8 | Out of bounds memory access in Skia in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-34622 | Medium | 0.4% | 8.6 | Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are… | |
| CVE-2026-19297 | Medium | 0.4% | 9.1 | IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain una… | |
| CVE-2026-81396 | Medium | 0.4% | 7.8 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized att… | |
| CVE-2026-81397 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… | |
| CVE-2026-81956 | Medium | 0.4% | 7.8 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2026-81957 | Medium | 0.4% | 7.8 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2026-81960 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… | |
| CVE-2026-34617 | Medium | 0.4% | 8.7 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Sc… | |
| CVE-2026-66814 | Medium | 0.4% | 8.8 | Insufficient granularity of access control in SQL Server allows an authorized at… | |
| CVE-2026-83948 | Medium | 0.4% | 8.0 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2026-56167 | Medium | 0.4% | 8.5 | Server-side request forgery (ssrf) in Azure AI Search allows an authorized attac… | |
| CVE-2026-50428 | Medium | 0.4% | 7.1 | Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys)… | |
| CVE-2026-69306 | Medium | 0.4% | 8.2 | Not failing securely ('failing open') in Visual Studio Code allows an unauthoriz… | |
| CVE-2026-9939 | Medium | 0.4% | 8.8 | Heap buffer overflow in WebCodecs in Google Chrome prior to 148.0.7778.216 allow… | |
| CVE-2026-10904 | Medium | 0.4% | 8.8 | Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allow… | |
| CVE-2026-10928 | Medium | 0.4% | 8.8 | Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-45636 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-69477 | Medium | 0.4% | 7.3 | Heap-based buffer overflow in Microsoft Office Access allows an authorized attac… | |
| CVE-2026-54999 | Medium | 0.4% | 8.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-69402 | Medium | 0.4% | 7.3 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-20923 | Medium | 0.4% | 7.8 | Use after free in Windows Management Services allows an authorized attacker to e… | |
| CVE-2026-42834 | Medium | 0.4% | 7.8 | Improper access control in Windows Admin Center allows an authorized attacker to… | |
| CVE-2026-62721 | Medium | 0.4% | 7.8 | Insufficient granularity of access control in User-Mode Power Service (UMPS) all… | |
| CVE-2023-21801 | Medium | 0.4% | 7.8 | Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnera… | |
| CVE-2026-68827 | Medium | 0.4% | 8.0 | Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized atta… | |
| CVE-2026-68838 | Medium | 0.4% | 8.0 | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to ele… | |
| CVE-2026-58641 | Medium | 0.4% | 7.8 | Integer overflow or wraparound in .NET allows an unauthorized attacker to elevat… | |
| CVE-2026-58651 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attac… | |
| CVE-2026-62886 | Medium | 0.4% | 7.8 | Integer overflow or wraparound in .NET allows an unauthorized attacker to elevat… | |
| CVE-2026-64914 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized att… | |
| CVE-2026-68812 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… | |
| CVE-2026-68814 | Medium | 0.4% | 7.8 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2026-68817 | Medium | 0.4% | 7.8 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized att… | |
| CVE-2026-19306 | Medium | 0.4% | 7.7 | IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read a… | |
| CVE-2026-48334 | Medium | 0.4% | 9.3 | Illustrator is affected by an Improper Input Validation vulnerability that could… | |
| CVE-2026-69419 | Medium | 0.4% | 8.5 | Integer overflow or wraparound in Azure Data Manager for Energy allows an author… | |
| CVE-2026-42909 | Medium | 0.4% | 7.5 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62871 | Medium | 0.4% | 7.8 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code loca… |