microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-62693 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62705 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62728 | Medium | 0.2% | 7.0 | Time-of-check time-of-use (toctou) race condition in Windows Common Log File Sys… | |
| CVE-2026-62729 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62734 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62748 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-69859 | Medium | 0.2% | 7.0 | Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class dri… | |
| CVE-2026-58598 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-69319 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-73005 | Medium | 0.2% | 7.0 | Use after free in Windows Authentication Methods allows an authorized attacker t… | |
| CVE-2026-78464 | Medium | 0.2% | 7.0 | Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module… | |
| CVE-2026-10926 | Medium | 0.2% | 8.8 | Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attack… | |
| CVE-2026-11304 | Medium | 0.2% | 8.8 | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-45597 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-10000 | Medium | 0.2% | 8.3 | Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 … | |
| CVE-2026-42977 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-42979 | Medium | 0.2% | 7.8 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-11693 | Medium | 0.2% | 8.1 | Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103… | |
| CVE-2026-27292 | Medium | 0.2% | 7.8 | Adobe Framemaker versions 2022.8 and earlier are affected by a Use After Free vu… | |
| CVE-2026-45487 | Medium | 0.2% | 7.8 | Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assis… | |
| CVE-2026-75631 | Medium | 0.2% | 7.8 | Photoshop Desktop is affected by an out-of-bounds write vulnerability that could… | |
| CVE-2026-82005 | Medium | 0.2% | 7.8 | Photoshop Desktop is affected by an out-of-bounds write vulnerability that could… | |
| CVE-2026-9982 | Medium | 0.2% | 8.3 | Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 14… | |
| CVE-2026-21342 | Medium | 0.2% | 7.8 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds… | |
| CVE-2026-68824 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-9994 | Medium | 0.2% | 8.3 | Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allow… | |
| CVE-2026-11236 | Medium | 0.2% | 8.3 | Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0… | |
| CVE-2026-47940 | Medium | 0.2% | 7.8 | Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability… | |
| CVE-2026-62727 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-10002 | Medium | 0.2% | 8.8 | Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remo… | |
| CVE-2026-11092 | Medium | 0.2% | 8.8 | Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827… | |
| CVE-2026-11679 | Medium | 0.2% | 8.3 | Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.103 all… | |
| CVE-2026-11692 | Medium | 0.2% | 8.3 | Use after free in Read Anything in Google Chrome prior to 149.0.7827.103 allowed… | |
| CVE-2026-11700 | Medium | 0.2% | 8.3 | Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a rem… | |
| CVE-2026-45596 | Medium | 0.2% | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-45598 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-45601 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-45603 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-27238 | Medium | 0.2% | 7.8 | InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based … | |
| CVE-2026-27267 | Medium | 0.2% | 7.8 | Illustrator versions 29.8.4, 30.1 and earlier are affected by a Stack-based Buff… | |
| CVE-2026-27271 | Medium | 0.2% | 7.8 | Illustrator versions 29.8.4, 30.1 and earlier are affected by a Heap-based Buffe… | |
| CVE-2026-33099 | Medium | 0.2% | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-33100 | Medium | 0.2% | 7.0 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-34707 | Medium | 0.2% | 7.8 | InCopy versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Ove… | |
| CVE-2026-79908 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by an out-of-bounds write vulnerability that could re… | |
| CVE-2026-81983 | Medium | 0.2% | 7.8 | Acrobat Reader is affected by an out-of-bounds write vulnerability that could re… | |
| CVE-2026-9997 | Medium | 0.2% | 8.3 | Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remot… | |
| CVE-2026-22561 | Medium | 0.2% | 7.8 | Uncontrolled search path elements in Anthropic Claude for Windows installer (Cla… | |
| CVE-2026-34638 | Medium | 0.2% | 7.8 | Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by a Use After Fre… | |
| CVE-2026-47906 | Medium | 0.2% | 8.6 | Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vu… |