microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-72990 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-72991 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-72992 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-72996 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-72997 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-73001 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-73021 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-77489 | Medium | 0.3% | 7.8 | Null pointer dereference in Windows Biometric Service allows an authorized attac… | |
| CVE-2026-80075 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Work Folders allows an authorized attacker… | |
| CVE-2026-83954 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83967 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83968 | Medium | 0.3% | 7.8 | Use after free in Windows Biometric Service allows an authorized attacker to ele… | |
| CVE-2026-83970 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83971 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83972 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83973 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83975 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83977 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83978 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83979 | Medium | 0.3% | 7.8 | Use after free in Windows Biometric Service allows an authorized attacker to ele… | |
| CVE-2026-83980 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83981 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83982 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83983 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83985 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83986 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83987 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-83988 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-9973 | Medium | 0.3% | 8.8 | Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a rem… | |
| CVE-2026-10949 | Medium | 0.3% | 8.3 | Heap buffer overflow in Video in Google Chrome prior to 149.0.7827.53 allowed a … | |
| CVE-2026-11011 | Medium | 0.3% | 8.1 | Insufficient policy enforcement in Password Manager in Google Chrome prior to 14… | |
| CVE-2026-33828 | Medium | 0.3% | 7.8 | Trust boundary violation in Windows Attestation allows an authorized attacker to… | |
| CVE-2026-45654 | Medium | 0.3% | 7.9 | Improper access control in Windows Secure Boot allows an authorized attacker to … | |
| CVE-2022-41093 | Medium | 0.3% | 7.8 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerabilit… | |
| CVE-2026-10968 | Medium | 0.3% | 7.4 | Insufficient validation of untrusted input in Dawn in Google Chrome on Windows p… | |
| CVE-2026-7344 | Medium | 0.3% | 8.8 | Use after free in Accessibility in Google Chrome on Windows prior to 147.0.7727.… | |
| CVE-2026-11683 | Medium | 0.3% | 8.8 | Use after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed a r… | |
| CVE-2026-19304 | Medium | 0.3% | 7.7 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke… | |
| CVE-2026-20877 | Medium | 0.3% | 7.8 | Use after free in Windows Management Services allows an authorized attacker to e… | |
| CVE-2026-20918 | Medium | 0.3% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-20924 | Medium | 0.3% | 7.8 | Use after free in Windows Management Services allows an authorized attacker to e… | |
| CVE-2026-33098 | Medium | 0.3% | 7.8 | Use after free in Windows Container Isolation FS Filter Driver allows an authori… | |
| CVE-2026-45641 | Medium | 0.3% | 8.4 | Access of resource using incompatible type ('type confusion') in Windows Hyper-V… | |
| CVE-2026-47915 | Medium | 0.3% | 7.8 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-47917 | Medium | 0.3% | 7.8 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-50451 | Medium | 0.3% | 7.1 | Missing authentication for critical function in Windows Routing and Remote Acces… | |
| CVE-2026-11117 | Medium | 0.3% | 8.8 | Use after free in Views in Google Chrome on Windows prior to 149.0.7827.53 allow… | |
| CVE-2026-14525 | Medium | 0.3% | 9.4 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphe… | |
| CVE-2026-7345 | Medium | 0.3% | 8.3 | Insufficient validation of untrusted input in Feedback in Google Chrome prior to… | |
| CVE-2026-10911 | Medium | 0.3% | 8.3 | Insufficient validation of untrusted input in Media in Google Chrome prior to 14… |