microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-38649 | Act now | 2.9% | 7.0 | ● | Open Management Infrastructure Elevation of Privilege Vulnerability |
| CVE-2021-38645 | Act now | 2.7% | 7.8 | ● | Open Management Infrastructure Elevation of Privilege Vulnerability |
| CVE-2024-38226 | Act now | 2.7% | 7.3 | ● | Microsoft Publisher Security Feature Bypass Vulnerability |
| CVE-2022-41049 | Act now | 2.5% | 5.4 | ● | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2019-1130 | Act now | 2.3% | 7.8 | ● | An elevation of privilege vulnerability exists when Windows AppX Deployment Serv… |
| CVE-2022-41073 | Act now | 2.3% | 7.8 | ● | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2026-11645 | Act now | 2.2% | 8.8 | ● | Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allo… |
| CVE-2022-41091 | Act now | 1.8% | 5.4 | ● | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2026-81963 | Act now | 0.6% | 7.8 | ● | Improper link resolution before file access ('link following') in Windows Update… |
| CVE-2026-85880 | Act now | 0.6% | 7.8 | ● | Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elev… |
| CVE-2021-41349 | High | 93.5% | 6.5 | Microsoft Exchange Server Spoofing Vulnerability | |
| CVE-2023-21716 | High | 82.3% | 9.8 | Microsoft Word Remote Code Execution Vulnerability | |
| CVE-2023-21707 | High | 82.0% | 8.8 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2023-36899 | High | 76.7% | 8.8 | ASP.NET Elevation of Privilege Vulnerability | |
| CVE-2021-27084 | High | 62.1% | 7.8 | Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability | |
| CVE-2021-27083 | High | 61.9% | 7.8 | Remote Development Extension for Visual Studio Code Remote Code Execution Vulner… | |
| CVE-2021-26424 | High | 61.1% | 9.9 | Windows TCP/IP Remote Code Execution Vulnerability | |
| CVE-2026-49160 | High | 53.8% | 7.5 | Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to d… | |
| CVE-2021-34501 | High | 51.4% | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | |
| CVE-2021-34478 | High | 51.2% | 7.8 | Microsoft Office Remote Code Execution Vulnerability | |
| CVE-2021-36952 | High | 51.2% | 7.8 | Visual Studio Remote Code Execution Vulnerability | |
| CVE-2021-27080 | High | 1.3% | 9.3 | Azure Sphere Unsigned Code Execution Vulnerability | |
| CVE-2026-28373 | High | 0.4% | 9.6 | The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path t… | |
| CVE-2026-87528 | High | 0.3% | 9.6 | Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 all… | |
| CVE-2021-34481 | Medium | 47.7% | 8.8 | A remote code execution vulnerability exists when the Windows Print Spooler serv… | |
| CVE-2023-21818 | Medium | 43.2% | 7.5 | Windows Secure Channel Denial of Service Vulnerability | |
| CVE-2026-45484 | Medium | 35.2% | 8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an autho… | |
| CVE-2021-34480 | Medium | 33.9% | 6.8 | Scripting Engine Memory Corruption Vulnerability | |
| CVE-2021-26412 | Medium | 33.8% | 9.1 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2023-21819 | Medium | 30.8% | 7.5 | Windows Secure Channel Denial of Service Vulnerability | |
| CVE-2021-36958 | Medium | 30.6% | 7.8 | A remote code execution vulnerability exists when the Windows Print Spooler serv… | |
| CVE-2023-21690 | Medium | 27.5% | 9.8 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execut… | |
| CVE-2024-21357 | Medium | 26.9% | 8.1 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | |
| CVE-2023-21689 | Medium | 26.5% | 9.8 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execut… | |
| CVE-2021-26854 | Medium | 23.6% | 6.6 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2026-47291 | Medium | 22.8% | 9.8 | Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attack… | |
| CVE-2024-43454 | Medium | 21.9% | 7.1 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | |
| CVE-2021-34535 | Medium | 21.7% | 8.8 | Remote Desktop Client Remote Code Execution Vulnerability | |
| CVE-2023-21692 | Medium | 21.2% | 9.8 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execut… | |
| CVE-2021-27078 | Medium | 20.6% | 9.1 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2026-45502 | Medium | 20.3% | 5.0 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an author… | |
| CVE-2026-20872 | Medium | 20.1% | 6.5 | External control of file name or path in Windows NTLM allows an unauthorized att… | |
| CVE-2026-20925 | Medium | 18.2% | 6.5 | External control of file name or path in Windows NTLM allows an unauthorized att… | |
| CVE-2021-26877 | Medium | 16.5% | 9.8 | Windows DNS Server Remote Code Execution Vulnerability | |
| CVE-2020-1048 | Medium | 16.4% | 7.8 | An elevation of privilege vulnerability exists when the Windows Print Spooler se… | |
| CVE-2020-1118 | Medium | 16.2% | 8.6 | A denial of service vulnerability exists in the Windows implementation of Transp… | |
| CVE-2026-45657 | Medium | 15.5% | 9.8 | Use after free in Windows Kernel allows an unauthorized attacker to execute code… | |
| CVE-2021-38666 | Medium | 15.1% | 8.8 | Remote Desktop Client Remote Code Execution Vulnerability | |
| CVE-2021-27076 | Medium | 14.4% | 8.8 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| CVE-2021-31206 | Medium | 13.0% | 7.6 | Microsoft Exchange Server Remote Code Execution Vulnerability |