microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-10945 | Medium | 0.4% | 8.8 | Use after free in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote a… | |
| CVE-2026-50348 | Medium | 0.4% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50452 | Medium | 0.4% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-66802 | Medium | 0.4% | 8.1 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-7333 | Medium | 0.4% | 9.6 | Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote … | |
| CVE-2026-7334 | Medium | 0.4% | 8.8 | Use after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed … | |
| CVE-2026-11662 | Medium | 0.4% | 8.8 | Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a re… | |
| CVE-2026-49789 | Medium | 0.4% | 7.3 | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to ele… | |
| CVE-2026-50482 | Medium | 0.4% | 7.3 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to exec… | |
| CVE-2026-50510 | Medium | 0.4% | 7.8 | Improper restriction of names for files and other resources in Github Copilot al… | |
| CVE-2026-58640 | Medium | 0.4% | 7.3 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to exec… | |
| CVE-2026-8854 | Medium | 0.4% | 7.5 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional… | |
| CVE-2026-19875 | Medium | 0.4% | 7.5 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite… | |
| CVE-2026-34691 | Medium | 0.4% | 9.3 | Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are af… | |
| CVE-2026-45607 | Medium | 0.4% | 8.4 | Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute… | |
| CVE-2026-27220 | Medium | 0.4% | 7.8 | Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are… | |
| CVE-2026-65656 | Medium | 0.4% | 7.8 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2026-79175 | Medium | 0.4% | 8.3 | Type confusion in Accessibility in Google Chrome on on Windows prior to 152.0.79… | |
| CVE-2026-11054 | Medium | 0.4% | 8.8 | Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-11068 | Medium | 0.4% | 8.8 | Use after free in WebSockets in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-62761 | Medium | 0.4% | 7.8 | Improper link resolution before file access ('link following') in Windows DHCP S… | |
| CVE-2026-81389 | Medium | 0.4% | 7.0 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… | |
| CVE-2026-9962 | Medium | 0.4% | 8.8 | Use after free in WebRTC in Google Chrome prior to 148.0.7778.216 allowed a remo… | |
| CVE-2026-11147 | Medium | 0.4% | 8.8 | Use after free in WebML in Google Chrome on Windows prior to 149.0.7827.53 allow… | |
| CVE-2026-79139 | Medium | 0.4% | 7.5 | Improper input validation in Media in Google Chrome on on Windows prior to 152.0… | |
| CVE-2026-45658 | Medium | 0.4% | 7.8 | Improper access control in Windows BitLocker allows an authorized attacker to by… | |
| CVE-2026-47631 | Medium | 0.4% | 8.1 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-11024 | Medium | 0.4% | 8.8 | Stack buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-63513 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t… | |
| CVE-2026-63515 | Medium | 0.4% | 7.8 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execut… | |
| CVE-2026-63518 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attac… | |
| CVE-2026-63519 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t… | |
| CVE-2026-65664 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t… | |
| CVE-2026-66807 | Medium | 0.4% | 7.8 | Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker … | |
| CVE-2026-68794 | Medium | 0.4% | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… | |
| CVE-2026-68804 | Medium | 0.4% | 7.8 | Numeric truncation error in Microsoft Office Excel allows an unauthorized attack… | |
| CVE-2026-5859 | Medium | 0.4% | 8.8 | Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remo… | |
| CVE-2026-75624 | Medium | 0.4% | 8.8 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.… | |
| CVE-2023-35378 | Medium | 0.4% | 7.0 | Windows Projected File System Elevation of Privilege Vulnerability | |
| CVE-2026-13445 | Medium | 0.4% | 8.1 | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exp… | |
| CVE-2026-48569 | Medium | 0.4% | 7.1 | Improper input validation in Visual Studio Code allows an unauthorized attacker … | |
| CVE-2023-21777 | Medium | 0.3% | 8.7 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | |
| CVE-2026-58647 | Medium | 0.3% | 8.0 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-81353 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unautho… | |
| CVE-2026-81386 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… | |
| CVE-2026-10886 | Medium | 0.3% | 9.6 | Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-45482 | Medium | 0.3% | 8.4 | Improper limitation of a pathname to a restricted directory ('path traversal') i… | |
| CVE-2026-87524 | Medium | 0.3% | 8.3 | Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 all… | |
| CVE-2022-38014 | Medium | 0.3% | 7.0 | Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability | |
| CVE-2026-47652 | Medium | 0.3% | 8.2 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to e… |