microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-65814 | Medium | 0.3% | 7.8 | Heap-based buffer overflow in Windows Storage Port Driver allows an authorized a… | |
| CVE-2026-8835 | Medium | 0.3% | 7.3 | IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A pri… | |
| CVE-2026-42984 | Medium | 0.3% | 7.0 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-45653 | Medium | 0.3% | 7.0 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to el… | |
| CVE-2026-62739 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to … | |
| CVE-2026-62771 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an a… | |
| CVE-2026-62894 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows DWM Core Library allows an authorized atta… | |
| CVE-2026-68792 | Medium | 0.2% | 7.8 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2026-82006 | Medium | 0.2% | 7.8 | Photoshop Desktop is affected by a Heap-based Buffer Overflow vulnerability that… | |
| CVE-2026-11091 | Medium | 0.2% | 8.8 | Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 all… | |
| CVE-2026-21268 | Medium | 0.2% | 8.6 | Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input … | |
| CVE-2026-21271 | Medium | 0.2% | 8.6 | Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input … | |
| CVE-2026-21275 | Medium | 0.2% | 7.8 | InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of … | |
| CVE-2026-21276 | Medium | 0.2% | 7.8 | InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of … | |
| CVE-2026-69890 | Medium | 0.2% | 7.5 | Use after free in Windows Virtual Trusted Platform Module allows an authorized a… | |
| CVE-2026-73017 | Medium | 0.2% | 7.5 | Heap-based buffer overflow in Windows Graphics Kernel allows an authorized attac… | |
| CVE-2026-42978 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50472 | Medium | 0.2% | 7.0 | Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to ele… | |
| CVE-2026-59125 | Medium | 0.2% | 7.0 | Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized a… | |
| CVE-2026-61346 | Medium | 0.2% | 7.0 | Use after free in Windows Graphics Kernel allows an authorized attacker to eleva… | |
| CVE-2026-61361 | Medium | 0.2% | 7.0 | Use after free in Windows DHCP Client allows an authorized attacker to execute c… | |
| CVE-2026-61366 | Medium | 0.2% | 7.0 | Double free in Windows Network Connection Broker allows an authorized attacker t… | |
| CVE-2026-61938 | Medium | 0.2% | 7.0 | Use after free in Windows Installer allows an authorized attacker to elevate pri… | |
| CVE-2026-61939 | Medium | 0.2% | 7.0 | Use after free in Winlogon allows an authorized attacker to elevate privileges l… | |
| CVE-2026-62694 | Medium | 0.2% | 7.0 | Use after free in Windows Installer allows an authorized attacker to elevate pri… | |
| CVE-2026-62723 | Medium | 0.2% | 7.0 | Use after free in Windows Telephony Service allows an authorized attacker to ele… | |
| CVE-2026-62724 | Medium | 0.2% | 7.0 | Use after free in Windows Telephony Service allows an authorized attacker to ele… | |
| CVE-2026-62726 | Medium | 0.2% | 7.0 | Use after free in Windows Telephony Service allows an authorized attacker to ele… | |
| CVE-2026-68825 | Medium | 0.2% | 7.0 | Use after free in Windows Bind Filter Driver allows an authorized attacker to el… | |
| CVE-2026-69287 | Medium | 0.2% | 7.0 | Use after free in Windows Remote Desktop Services allows an authorized attacker … | |
| CVE-2026-69333 | Medium | 0.2% | 7.0 | Use after free in Windows Win32K allows an authorized attacker to elevate privil… | |
| CVE-2026-69413 | Medium | 0.2% | 7.0 | Use after free in Windows USB Audio Class driver (usbaudio.sys) allows an author… | |
| CVE-2026-69422 | Medium | 0.2% | 7.0 | Use after free in Windows USB Video Driver allows an authorized attacker to elev… | |
| CVE-2026-69567 | Medium | 0.2% | 7.0 | Use after free in Windows NTFS allows an authorized attacker to elevate privileg… | |
| CVE-2026-69574 | Medium | 0.2% | 7.0 | Use after free in Windows Device Association Service allows an authorized attack… | |
| CVE-2026-69814 | Medium | 0.2% | 7.0 | Use after free in Windows Credential Providers allows an authorized attacker to … | |
| CVE-2026-69816 | Medium | 0.2% | 7.0 | Use after free in Windows Accounts Control allows an authorized attacker to elev… | |
| CVE-2026-69817 | Medium | 0.2% | 7.0 | Use after free in Windows Bluetooth Port Driver allows an authorized attacker to… | |
| CVE-2026-69818 | Medium | 0.2% | 7.0 | Use after free in Windows Win32K allows an authorized attacker to elevate privil… | |
| CVE-2026-69834 | Medium | 0.2% | 7.0 | Use after free in Windows ALPC allows an authorized attacker to elevate privileg… | |
| CVE-2026-69838 | Medium | 0.2% | 7.0 | Use after free in Windows Print Spooler Components allows an authorized attacker… | |
| CVE-2026-69866 | Medium | 0.2% | 7.0 | Use after free in Windows Device Association Service allows an authorized attack… | |
| CVE-2026-69889 | Medium | 0.2% | 7.0 | Use after free in Windows Bluetooth Service allows an authorized attacker to ele… | |
| CVE-2026-69891 | Medium | 0.2% | 7.0 | Use after free in Windows Media allows an authorized attacker to elevate privile… | |
| CVE-2026-69896 | Medium | 0.2% | 7.0 | Use after free in Windows Error Reporting allows an authorized attacker to eleva… | |
| CVE-2026-70562 | Medium | 0.2% | 7.0 | Double free in Windows Audio Service allows an authorized attacker to elevate pr… | |
| CVE-2026-70565 | Medium | 0.2% | 7.0 | Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker … | |
| CVE-2026-70567 | Medium | 0.2% | 7.0 | Double free in Windows Display Enhancement Service allows an authorized attacker… | |
| CVE-2026-70568 | Medium | 0.2% | 7.0 | Heap-based buffer overflow in Windows Defender Firewall Service allows an author… | |
| CVE-2026-71332 | Medium | 0.2% | 7.0 | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an auth… |