microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-9975 | Medium | 0.2% | 8.3 | Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 a… | |
| CVE-2026-81975 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Use After Free vulnerability that could result i… | |
| CVE-2026-11256 | Medium | 0.2% | 8.3 | Integer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-21287 | Medium | 0.2% | 7.8 | Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free… | |
| CVE-2026-5902 | Medium | 0.2% | 9.8 | Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remot… | |
| CVE-2026-11169 | Medium | 0.2% | 8.1 | Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-6406 | Medium | 0.2% | 8.8 | The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI)… | |
| CVE-2026-76199 | Medium | 0.2% | 8.6 | Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerabili… | |
| CVE-2026-83999 | Medium | 0.2% | 7.0 | Improper link resolution before file access ('link following') in Windows Resili… | |
| CVE-2026-11301 | Medium | 0.2% | 8.8 | Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827… | |
| CVE-2026-34687 | Medium | 0.2% | 7.8 | Illustrator versions 29.8.6, 30.3 and earlier are affected by a Heap-based Buffe… | |
| CVE-2026-47916 | Medium | 0.2% | 7.8 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-81992 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that co… | |
| CVE-2026-11058 | Medium | 0.2% | 7.5 | Integer overflow in CredentialProvider in Google Chrome on Windows prior to 149.… | |
| CVE-2026-11154 | Medium | 0.2% | 7.5 | Use after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote … | |
| CVE-2026-33104 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62753 | Medium | 0.2% | 7.0 | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to … | |
| CVE-2026-76037 | Medium | 0.2% | 8.4 | Link following in CredentialProvider in Google Chrome on on Windows prior to 151… | |
| CVE-2026-9946 | Medium | 0.2% | 8.3 | Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-9974 | Medium | 0.2% | 8.3 | Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a re… | |
| CVE-2026-11201 | Medium | 0.2% | 8.8 | Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed … | |
| CVE-2026-69646 | Medium | 0.2% | 8.3 | Improper verification of cryptographic signature in Skype for Business allows an… | |
| CVE-2026-27287 | Medium | 0.2% | 7.8 | InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read v… | |
| CVE-2026-42912 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-5913 | Medium | 0.2% | 8.1 | Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a re… | |
| CVE-2026-11265 | Medium | 0.2% | 7.5 | Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-11697 | Medium | 0.2% | 9.6 | Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0… | |
| CVE-2026-11293 | Medium | 0.2% | 9.6 | Use after free in Input in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-44800 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-49183 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-49784 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-49802 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-49803 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-49806 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-49808 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50322 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50345 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50356 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50371 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50384 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50403 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50404 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50450 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50503 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50658 | Medium | 0.2% | 7.0 | Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows a… | |
| CVE-2026-50669 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-50672 | Medium | 0.2% | 7.0 | Use after free in Windows NTFS allows an authorized attacker to elevate privileg… | |
| CVE-2026-54111 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-58628 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62780 | Medium | 0.2% | 7.0 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… |