microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-9949 | Medium | 0.2% | 8.3 | Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allow… | |
| CVE-2026-9951 | Medium | 0.2% | 8.3 | Use after free in UI in Google Chrome prior to 148.0.7778.216 allowed a remote a… | |
| CVE-2026-10003 | Medium | 0.2% | 7.5 | Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-10009 | Medium | 0.2% | 7.5 | Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remo… | |
| CVE-2026-11149 | Medium | 0.2% | 7.5 | Insufficient validation of untrusted input in Extensions in Google Chrome prior … | |
| CVE-2026-11151 | Medium | 0.2% | 7.5 | Insufficient validation of untrusted input in Password Manager in Google Chrome … | |
| CVE-2026-11239 | Medium | 0.2% | 7.5 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-27309 | Medium | 0.2% | 7.8 | Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free… | |
| CVE-2026-70283 | Medium | 0.2% | 7.0 | Incorrect authorization in Windows Win32K allows an authorized attacker to eleva… | |
| CVE-2026-21321 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an Integer Overflow or W… | |
| CVE-2026-21322 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds read vu… | |
| CVE-2026-21324 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds read vu… | |
| CVE-2026-21325 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds read vu… | |
| CVE-2026-21330 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an Access of Resource Us… | |
| CVE-2026-11689 | Medium | 0.2% | 8.1 | Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.782… | |
| CVE-2026-47648 | Medium | 0.2% | 7.0 | Untrusted search path in Windows Storage allows an authorized attacker to elevat… | |
| CVE-2026-48348 | Medium | 0.2% | 7.7 | Animate is affected by an Incorrect Authorization vulnerability that could resul… | |
| CVE-2026-9887 | Medium | 0.2% | 8.8 | Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-11707 | Medium | 0.2% | 9.3 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Applicati… | |
| CVE-2026-11070 | Medium | 0.2% | 9.6 | Insufficient validation of untrusted input in Chromoting in Google Chrome on Win… | |
| CVE-2026-11079 | Medium | 0.2% | 8.8 | Insufficient validation of untrusted input in Codecs in Google Chrome prior to 1… | |
| CVE-2026-11198 | Medium | 0.2% | 9.6 | Insufficient validation of untrusted input in Codecs in Google Chrome prior to 1… | |
| CVE-2026-11207 | Medium | 0.2% | 9.6 | Insufficient validation of untrusted input in Autofill in Google Chrome prior to… | |
| CVE-2026-47304 | Medium | 0.2% | 8.1 | Improper verification of cryptographic signature in .NET allows an unauthorized … | |
| CVE-2026-50523 | Medium | 0.2% | 7.8 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2026-8670 | Medium | 0.2% | 9.6 | Insufficient session expiration vulnerability in syslink software AG Avantra on … | |
| CVE-2026-8671 | Medium | 0.2% | 7.5 | Insertion of sensitive information into log file vulnerability in syslink softwa… | |
| CVE-2026-11667 | Medium | 0.2% | 7.5 | Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.103 allowed a … | |
| CVE-2026-5912 | Medium | 0.2% | 8.8 | Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a rem… | |
| CVE-2026-11694 | Medium | 0.2% | 7.5 | Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed… | |
| CVE-2026-42976 | Medium | 0.2% | 7.8 | Missing authentication for critical function in Windows RPC API allows an author… | |
| CVE-2026-50317 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50321 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50378 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50440 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50667 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50676 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-58526 | Medium | 0.2% | 7.0 | Use after free in Windows Storage allows an authorized attacker to elevate privi… | |
| CVE-2026-58527 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-58611 | Medium | 0.2% | 7.8 | Improper authorization in XBox Gaming Services allows an authorized attacker to … | |
| CVE-2026-62777 | Medium | 0.2% | 7.8 | Missing authentication for critical function in Windows License Manager allows a… | |
| CVE-2026-65678 | Medium | 0.2% | 7.0 | Use after free in Windows Win32K allows an authorized attacker to elevate privil… | |
| CVE-2026-65778 | Medium | 0.2% | 7.0 | Use after free in Windows Autopilot allows an authorized attacker to elevate pri… | |
| CVE-2026-65779 | Medium | 0.2% | 7.0 | Use after free in Windows Autopilot allows an authorized attacker to elevate pri… | |
| CVE-2026-83942 | Medium | 0.2% | 7.8 | Missing authorization in Windows Kernel allows an authorized attacker to elevate… | |
| CVE-2026-9890 | Medium | 0.2% | 8.3 | Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed… | |
| CVE-2026-9905 | Medium | 0.2% | 8.3 | Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.… | |
| CVE-2026-9954 | Medium | 0.2% | 7.5 | Use after free in TabStrip in Google Chrome prior to 148.0.7778.216 allowed a re… | |
| CVE-2026-9966 | Medium | 0.2% | 8.3 | Integer overflow in XML in Google Chrome on Windows prior to 148.0.7778.216 allo… | |
| CVE-2026-9970 | Medium | 0.2% | 8.3 | Use after free in WebGL in Google Chrome prior to 148.0.7778.216 allowed a remot… |