microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-71333 | Medium | 0.2% | 7.0 | Use after free in Windows Remote Access Connection Manager allows an authorized … | |
| CVE-2026-71342 | Medium | 0.2% | 7.0 | Use after free in Windows Remote Access Connection Manager allows an authorized … | |
| CVE-2026-72963 | Medium | 0.2% | 7.0 | Use after free in Windows Modern Execution Server allows an authorized attacker … | |
| CVE-2026-83940 | Medium | 0.2% | 7.0 | Use after free in Windows Device Association Service allows an authorized attack… | |
| CVE-2026-9924 | Medium | 0.2% | 8.3 | Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.21… | |
| CVE-2026-9926 | Medium | 0.2% | 8.3 | Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a… | |
| CVE-2026-9891 | Medium | 0.2% | 9.0 | Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a … | |
| CVE-2026-32224 | Medium | 0.2% | 7.0 | Use after free in Windows Server Update Service allows an authorized attacker to… | |
| CVE-2026-11671 | Medium | 0.2% | 9.6 | Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a … | |
| CVE-2026-11673 | Medium | 0.2% | 8.8 | Use after free in InterestGroups in Google Chrome prior to 149.0.7827.103 allowe… | |
| CVE-2026-11674 | Medium | 0.2% | 8.8 | Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a … | |
| CVE-2026-11680 | Medium | 0.2% | 8.8 | Use after free in Media in Google Chrome on Windows prior to 149.0.7827.103 allo… | |
| CVE-2026-9961 | Medium | 0.2% | 8.8 | Use after free in SurfaceCapture in Google Chrome prior to 148.0.7778.216 allowe… | |
| CVE-2026-9965 | Medium | 0.2% | 8.8 | Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a … | |
| CVE-2026-9967 | Medium | 0.2% | 9.6 | Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a re… | |
| CVE-2026-11230 | Medium | 0.2% | 8.8 | Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-11235 | Medium | 0.2% | 8.8 | Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7… | |
| CVE-2026-11652 | Medium | 0.2% | 8.3 | Use after free in Extensions in Google Chrome prior to 149.0.7827.103 allowed a … | |
| CVE-2026-11661 | Medium | 0.2% | 8.3 | Use after free in Views in Google Chrome on Windows prior to 149.0.7827.103 allo… | |
| CVE-2026-65773 | Medium | 0.2% | 7.8 | Improper access control in Windows Kernel allows an authorized attacker to eleva… | |
| CVE-2026-66318 | Medium | 0.2% | 8.1 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorize… | |
| CVE-2026-77503 | Medium | 0.2% | 8.4 | Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate pr… | |
| CVE-2026-11248 | Medium | 0.2% | 8.8 | Inappropriate implementation in Google Lens in Google Chrome prior to 149.0.7827… | |
| CVE-2026-63522 | Medium | 0.2% | 7.8 | Incorrect permission assignment for critical resource in Azure SQL Database allo… | |
| CVE-2026-62733 | Medium | 0.2% | 7.8 | Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate pr… | |
| CVE-2026-62736 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker … | |
| CVE-2026-62755 | Medium | 0.2% | 7.8 | Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker… | |
| CVE-2026-62758 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Remote Access Connection Manager allows an… | |
| CVE-2026-62770 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Shell allows an authorized attacker to ele… | |
| CVE-2026-62772 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unio… | |
| CVE-2026-62779 | Medium | 0.2% | 7.8 | Use after free in Windows Schannel allows an authorized attacker to elevate priv… | |
| CVE-2026-62876 | Medium | 0.2% | 7.8 | Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate pr… | |
| CVE-2026-62877 | Medium | 0.2% | 7.8 | Stack-based buffer overflow in Windows Win32K allows an authorized attacker to e… | |
| CVE-2026-62880 | Medium | 0.2% | 7.8 | Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate priv… | |
| CVE-2026-62885 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Win32K allows an authorized attacker to el… | |
| CVE-2026-65786 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Desktop Window Manager allows an authorized attack… | |
| CVE-2026-65790 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Message Queuing allows an authorized attac… | |
| CVE-2026-68787 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execut… | |
| CVE-2026-68832 | Medium | 0.2% | 7.8 | Integer overflow or wraparound in Windows NTFS allows an authorized attacker to … | |
| CVE-2026-68841 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elev… | |
| CVE-2026-68848 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Print Spooler Components allows an authori… | |
| CVE-2026-68875 | Medium | 0.2% | 7.8 | Buffer over-read in Windows NTFS allows an authorized attacker to execute code l… | |
| CVE-2026-69265 | Medium | 0.2% | 7.8 | Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate priv… | |
| CVE-2026-69270 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allo… | |
| CVE-2026-69293 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-70345 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Installer allows an authorized attacker to… | |
| CVE-2026-71334 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attack… | |
| CVE-2026-72988 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-72993 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… | |
| CVE-2026-72994 | Medium | 0.2% | 7.8 | Heap-based buffer overflow in Windows Biometric Service allows an authorized att… |