microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-80093 | Medium | 0.3% | 7.0 | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized at… | |
| CVE-2026-63526 | Medium | 0.3% | 7.8 | Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker … | |
| CVE-2026-63532 | Medium | 0.3% | 7.8 | Integer overflow or wraparound in Microsoft Office allows an unauthorized attack… | |
| CVE-2026-64898 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t… | |
| CVE-2026-64903 | Medium | 0.3% | 7.8 | Integer overflow or wraparound in Microsoft Office allows an unauthorized attack… | |
| CVE-2026-64907 | Medium | 0.3% | 7.8 | Stack-based buffer overflow in Microsoft Office Word allows an unauthorized atta… | |
| CVE-2026-64909 | Medium | 0.3% | 7.8 | Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorize… | |
| CVE-2026-64910 | Medium | 0.3% | 7.8 | Untrusted pointer dereference in Microsoft Office allows an unauthorized attacke… | |
| CVE-2026-64911 | Medium | 0.3% | 7.8 | Integer overflow or wraparound in Microsoft Office allows an unauthorized attack… | |
| CVE-2026-66315 | Medium | 0.3% | 7.5 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke… | |
| CVE-2026-68816 | Medium | 0.3% | 7.8 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized att… | |
| CVE-2026-71343 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Remote Access Connection Manager allows an… | |
| CVE-2026-7754 | Medium | 0.3% | 7.7 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side req… | |
| CVE-2026-40404 | Medium | 0.3% | 7.8 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege V… | |
| CVE-2026-65818 | Medium | 0.3% | 8.5 | Server-side request forgery (ssrf) in Power Automate allows an authorized attack… | |
| CVE-2026-69479 | Medium | 0.3% | 8.4 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-69638 | Medium | 0.3% | 8.4 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-69921 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Print Spooler Components allows an authori… | |
| CVE-2026-70289 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorize… | |
| CVE-2026-49165 | Medium | 0.3% | 7.1 | Use of uninitialized resource in Microsoft Windows App Store allows an authorize… | |
| CVE-2026-50680 | Medium | 0.3% | 8.2 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to e… | |
| CVE-2026-87494 | Medium | 0.3% | 9.6 | Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 … | |
| CVE-2026-11651 | Medium | 0.3% | 9.6 | Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a rem… | |
| CVE-2026-48339 | Medium | 0.3% | 7.8 | Bridge is affected by a Heap-based Buffer Overflow vulnerability that could resu… | |
| CVE-2026-48373 | Medium | 0.3% | 7.8 | Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that co… | |
| CVE-2026-49184 | Medium | 0.3% | 8.4 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-32193 | Medium | 0.3% | 8.8 | Improper limitation of a pathname to a restricted directory ('path traversal') i… | |
| CVE-2026-62897 | Medium | 0.3% | 7.0 | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker… | |
| CVE-2026-62914 | Medium | 0.3% | 7.3 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-61359 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Storage allows an authorized attacker to e… | |
| CVE-2026-62797 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elev… | |
| CVE-2026-62811 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to … | |
| CVE-2026-80098 | Medium | 0.3% | 9.3 | Improper verification of cryptographic signature in Copilot Studio allows an una… | |
| CVE-2024-4944 | Medium | 0.3% | 7.8 | A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL … | |
| CVE-2026-10978 | Medium | 0.3% | 8.8 | Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 … | |
| CVE-2026-42982 | Medium | 0.3% | 7.8 | Improper validation of consistency within input in Windows Secure Kernel Mode al… | |
| CVE-2026-47635 | Medium | 0.3% | 8.4 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t… | |
| CVE-2026-49166 | Medium | 0.3% | 7.8 | Use after free in Microsoft Printer Drivers allows an authorized attacker to ele… | |
| CVE-2026-49173 | Medium | 0.3% | 7.8 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-49175 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to eleva… | |
| CVE-2026-49783 | Medium | 0.3% | 7.8 | Improperly implemented security check for standard in Windows Secure Boot allows… | |
| CVE-2026-49792 | Medium | 0.3% | 7.8 | Numeric truncation error in Windows Resilient File System (ReFS) allows an autho… | |
| CVE-2026-49793 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an aut… | |
| CVE-2026-49795 | Medium | 0.3% | 8.8 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-49800 | Medium | 0.3% | 7.8 | Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPA… | |
| CVE-2026-50293 | Medium | 0.3% | 7.8 | Use after free in Windows Internal Task Bar allows an authorized attacker to ele… | |
| CVE-2026-50306 | Medium | 0.3% | 7.8 | Use after free in Windows TCP/IP allows an authorized attacker to elevate privil… | |
| CVE-2026-50309 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to exec… | |
| CVE-2026-50315 | Medium | 0.3% | 7.8 | Null pointer dereference in Windows Image Acquisition allows an authorized attac… | |
| CVE-2026-50326 | Medium | 0.3% | 7.8 | Use after free in Windows Unified Consent System allows an authorized attacker t… |