microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-58532 | Medium | 0.3% | 7.8 | Integer overflow or wraparound in Windows Kernel allows an authorized attacker t… | |
| CVE-2026-58534 | Medium | 0.3% | 8.8 | Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an auth… | |
| CVE-2026-58536 | Medium | 0.3% | 7.8 | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized at… | |
| CVE-2026-58537 | Medium | 0.3% | 7.8 | Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an autho… | |
| CVE-2026-58538 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Bluetooth Service allows an authorized att… | |
| CVE-2026-58541 | Medium | 0.3% | 7.8 | Access of resource using incompatible type ('type confusion') in Windows DWM all… | |
| CVE-2026-58601 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an … | |
| CVE-2026-58602 | Medium | 0.3% | 7.8 | Use after free in Windows Kernel Mode Driver allows an authorized attacker to el… | |
| CVE-2026-58632 | Medium | 0.3% | 7.8 | Use after free in Windows Win32K allows an authorized attacker to elevate privil… | |
| CVE-2026-62788 | Medium | 0.3% | 7.0 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-69476 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-7354 | Medium | 0.3% | 8.8 | Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 a… | |
| CVE-2026-7359 | Medium | 0.3% | 8.8 | Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remot… | |
| CVE-2026-10898 | Medium | 0.3% | 8.3 | Stack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-7339 | Medium | 0.3% | 8.8 | Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed … | |
| CVE-2026-5871 | Medium | 0.3% | 8.8 | Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote at… | |
| CVE-2026-9121 | Medium | 0.3% | 8.8 | Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a … | |
| CVE-2026-47912 | Medium | 0.3% | 7.8 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-47913 | Medium | 0.3% | 7.8 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-47914 | Medium | 0.3% | 7.8 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-50511 | Medium | 0.3% | 7.8 | Improper link resolution before file access ('link following') in Microsoft PC M… | |
| CVE-2026-48350 | Medium | 0.3% | 8.6 | Animate is affected by an Improper Limitation of a Pathname to a Restricted Dire… | |
| CVE-2026-77500 | Medium | 0.3% | 7.8 | Release of invalid pointer or reference in Windows Device Association Service al… | |
| CVE-2026-10906 | Medium | 0.3% | 7.5 | Use after free in WebAuthentication in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-42828 | Medium | 0.3% | 7.8 | Buffer over-read in Windows Projected File System Filter Driver allows an author… | |
| CVE-2026-42837 | Medium | 0.3% | 7.8 | Out-of-bounds read in Windows Projected File System Filter Driver allows an auth… | |
| CVE-2026-42916 | Medium | 0.3% | 7.8 | Integer overflow or wraparound in Windows NT OS Kernel allows an authorized atta… | |
| CVE-2026-69467 | Medium | 0.3% | 7.8 | Stack-based buffer overflow in Microsoft Graphics Component allows an authorized… | |
| CVE-2026-7361 | Medium | 0.3% | 8.8 | Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote … | |
| CVE-2026-10897 | Medium | 0.3% | 8.8 | Inappropriate implementation in GPU in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-10907 | Medium | 0.3% | 8.8 | Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-11009 | Medium | 0.3% | 9.6 | Use after free in USB in Google Chrome on Windows prior to 149.0.7827.53 allowed… | |
| CVE-2026-11021 | Medium | 0.3% | 9.6 | Insufficient validation of untrusted input in GPU in Google Chrome on Windows pr… | |
| CVE-2026-20844 | Medium | 0.3% | 7.4 | Use after free in Windows Clipboard Server allows an unauthorized attacker to el… | |
| CVE-2026-62804 | Medium | 0.3% | 7.8 | External control of file name or path in Microsoft Office Word allows an unautho… | |
| CVE-2026-65661 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t… | |
| CVE-2026-68793 | Medium | 0.3% | 7.8 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2026-68795 | Medium | 0.3% | 7.8 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized att… | |
| CVE-2026-68796 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… | |
| CVE-2026-68800 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… | |
| CVE-2026-68801 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… | |
| CVE-2026-68805 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… | |
| CVE-2026-70313 | Medium | 0.3% | 7.8 | Improper input validation in Microsoft Office PowerPoint allows an unauthorized … | |
| CVE-2026-9910 | Medium | 0.3% | 8.8 | Out of bounds memory access in ANGLE in Google Chrome prior to 148.0.7778.216 al… | |
| CVE-2026-10971 | Medium | 0.3% | 9.6 | Insufficient validation of untrusted input in Printing in Google Chrome on Windo… | |
| CVE-2026-19163 | Medium | 0.3% | 8.3 | Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allo… | |
| CVE-2026-45476 | Medium | 0.3% | 8.2 | Use after free in Linux MANA Driver allows an authorized attacker to elevate pri… | |
| CVE-2026-87621 | Medium | 0.3% | 9.6 | Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.… | |
| CVE-2026-70130 | Medium | 0.3% | 8.4 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker t… | |
| CVE-2026-81398 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized atta… |