microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-69466 | Medium | 0.2% | 7.0 | Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an au… | |
| CVE-2026-11185 | Medium | 0.2% | 8.1 | Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed an attacker… | |
| CVE-2026-62725 | Medium | 0.2% | 7.0 | Use after free in Windows Telephony Service allows an authorized attacker to ele… | |
| CVE-2026-62749 | Medium | 0.2% | 7.0 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-62773 | Medium | 0.2% | 7.0 | Use after free in Windows Kerberos allows an authorized attacker to elevate priv… | |
| CVE-2026-62774 | Medium | 0.2% | 7.0 | Use after free in Windows Graphics Kernel allows an authorized attacker to eleva… | |
| CVE-2026-62892 | Medium | 0.2% | 7.0 | Use after free in Capability Access Management Service (camsvc) allows an author… | |
| CVE-2026-65780 | Medium | 0.2% | 7.0 | Double free in Windows Autopilot allows an authorized attacker to elevate privil… | |
| CVE-2026-65781 | Medium | 0.2% | 7.0 | Use after free in Windows Autopilot allows an authorized attacker to elevate pri… | |
| CVE-2026-65782 | Medium | 0.2% | 7.0 | Use after free in Windows Autopilot allows an authorized attacker to elevate pri… | |
| CVE-2026-65783 | Medium | 0.2% | 7.0 | Use after free in Windows Autopilot allows an authorized attacker to elevate pri… | |
| CVE-2026-68837 | Medium | 0.2% | 7.0 | Use after free in Windows File History Service allows an authorized attacker to … | |
| CVE-2026-69578 | Medium | 0.2% | 7.0 | Numeric truncation error in Windows Kernel allows an authorized attacker to elev… | |
| CVE-2026-71399 | Medium | 0.2% | 7.8 | Adobe XD is affected by a Buffer Overflow vulnerability that could result in arb… | |
| CVE-2026-73003 | Medium | 0.2% | 7.0 | Use after free in Windows Modern Device Management (MDM) allows an authorized at… | |
| CVE-2026-73022 | Medium | 0.2% | 7.0 | Use after free in Windows Modern Device Management (MDM) allows an authorized at… | |
| CVE-2026-77485 | Medium | 0.2% | 7.0 | Use after free in SQL Server allows an authorized attacker to elevate privileges… | |
| CVE-2026-77899 | Medium | 0.2% | 7.0 | Use after free in Windows Security Center allows an authorized attacker to eleva… | |
| CVE-2026-77905 | Medium | 0.2% | 7.0 | Use after free in Windows Management Instrumentation allows an authorized attack… | |
| CVE-2026-78457 | Medium | 0.2% | 7.0 | Use after free in Windows Security Health Service allows an authorized attacker … | |
| CVE-2026-42836 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-81973 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Use After Free vulnerability that could result i… | |
| CVE-2026-81976 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Use After Free vulnerability that could result i… | |
| CVE-2026-81985 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Use After Free vulnerability that could result i… | |
| CVE-2026-81986 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Use After Free vulnerability that could result i… | |
| CVE-2026-81988 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Use After Free vulnerability that could result i… | |
| CVE-2026-81989 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Use After Free vulnerability that could result i… | |
| CVE-2026-32153 | Medium | 0.2% | 7.8 | Use after free in Microsoft Windows Speech allows an authorized attacker to elev… | |
| CVE-2026-8856 | Medium | 0.2% | 7.7 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configuration… | |
| CVE-2026-11213 | Medium | 0.2% | 9.6 | Insufficient validation of untrusted input in Reading Mode in Google Chrome prio… | |
| CVE-2026-5908 | Medium | 0.2% | 8.8 | Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remo… | |
| CVE-2026-5909 | Medium | 0.2% | 8.8 | Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remo… | |
| CVE-2026-5910 | Medium | 0.2% | 8.8 | Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remo… | |
| CVE-2026-27293 | Medium | 0.2% | 7.8 | Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer… | |
| CVE-2026-34618 | Medium | 0.2% | 7.8 | Illustrator versions 30.2, 29.8.5 and earlier are affected by an out-of-bounds w… | |
| CVE-2026-5915 | Medium | 0.2% | 8.1 | Insufficient validation of untrusted input in WebML in Google Chrome prior to 14… | |
| CVE-2026-48441 | Medium | 0.2% | 8.6 | Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restr… | |
| CVE-2026-21318 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds write v… | |
| CVE-2026-21327 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds write v… | |
| CVE-2026-21328 | Medium | 0.2% | 7.8 | After Effects versions 25.6 and earlier are affected by an out-of-bounds write v… | |
| CVE-2026-10019 | Medium | 0.2% | 8.8 | Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a rem… | |
| CVE-2026-79907 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by a Double Free vulnerability that could result in a… | |
| CVE-2026-80161 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Ty… | |
| CVE-2026-81987 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability th… | |
| CVE-2026-50349 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-5907 | Medium | 0.2% | 8.1 | Insufficient data validation in Media in Google Chrome prior to 147.0.7727.55 al… | |
| CVE-2026-59122 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-59126 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-61927 | Medium | 0.2% | 7.0 | Use after free in Windows Bind Filter Driver allows an authorized attacker to el… | |
| CVE-2026-62690 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … |