microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-48404 | Medium | 0.2% | 7.8 | Lightroom Classic is affected by an out-of-bounds write vulnerability that could… | |
| CVE-2026-48405 | Medium | 0.2% | 7.8 | Lightroom Classic is affected by an out-of-bounds write vulnerability that could… | |
| CVE-2026-48406 | Medium | 0.2% | 7.8 | Lightroom Classic is affected by an out-of-bounds write vulnerability that could… | |
| CVE-2026-48407 | Medium | 0.2% | 7.8 | Lightroom Classic is affected by an out-of-bounds write vulnerability that could… | |
| CVE-2026-48408 | Medium | 0.2% | 7.8 | Lightroom Classic is affected by an out-of-bounds write vulnerability that could… | |
| CVE-2026-48409 | Medium | 0.2% | 7.8 | Lightroom Classic is affected by an out-of-bounds write vulnerability that could… | |
| CVE-2026-48410 | Medium | 0.2% | 7.8 | Lightroom Classic is affected by an out-of-bounds write vulnerability that could… | |
| CVE-2026-27295 | Medium | 0.2% | 7.8 | Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds wr… | |
| CVE-2026-62908 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-66322 | Medium | 0.2% | 7.1 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorize… | |
| CVE-2026-68840 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-7338 | Medium | 0.2% | 7.5 | Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attac… | |
| CVE-2026-77894 | Medium | 0.2% | 7.0 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-10022 | Medium | 0.2% | 7.5 | Type Confusion in V8 in Google Chrome prior to 148.0.7778.216 allowed an attacke… | |
| CVE-2026-47937 | Medium | 0.2% | 7.7 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-4793 | Medium | 0.2% | 7.3 | An incorrect default permissions vulnerability in Synology Assistant before 7.0.… | |
| CVE-2026-6851 | Medium | 0.1% | 7.0 | An Improper link resolution before file access ('link following') vulnerability … | |
| CVE-2026-34636 | Medium | 0.1% | 7.8 | Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bound… | |
| CVE-2026-34637 | Medium | 0.1% | 7.8 | Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bound… | |
| CVE-2026-47965 | Medium | 0.1% | 7.8 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-21341 | Medium | 0.1% | 7.8 | Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds… | |
| CVE-2026-21346 | Medium | 0.1% | 7.8 | Bridge versions 15.1.3, 16.0.1 and earlier are affected by an out-of-bounds writ… | |
| CVE-2026-48447 | Medium | 0.1% | 7.7 | Lightroom Classic is affected by an Incorrect Authorization vulnerability that c… | |
| CVE-2026-27273 | Medium | 0.1% | 7.8 | Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds… | |
| CVE-2026-27275 | Medium | 0.1% | 7.8 | Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds… | |
| CVE-2026-27279 | Medium | 0.1% | 7.8 | Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds… | |
| CVE-2026-21362 | Medium | 0.1% | 7.8 | Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds w… | |
| CVE-2026-27274 | Medium | 0.1% | 7.8 | Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds… | |
| CVE-2026-34641 | Medium | 0.1% | 7.8 | Premiere Pro is affected by an out-of-bounds write vulnerability that could resu… | |
| CVE-2026-34700 | Medium | 0.1% | 7.8 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bou… | |
| CVE-2026-34706 | Medium | 0.1% | 7.8 | InCopy versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write … | |
| CVE-2026-48293 | Medium | 0.1% | 7.8 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bou… | |
| CVE-2026-27272 | Medium | 0.1% | 7.8 | Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds w… | |
| CVE-2026-34631 | Medium | 0.1% | 7.8 | InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write … | |
| CVE-2025-7024 | Medium | 0.1% | 7.3 | Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Ser… | |
| CVE-2026-87530 | Medium | 0.1% | 8.1 | Uncontrolled search path element in CredentialProvider in Google Chrome on on Wi… | |
| CVE-2026-11980 | Medium | 0.1% | 7.3 | IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution b… | |
| CVE-2026-81996 | Medium | 0.1% | 8.8 | Acrobat Reader is affected by an Incorrect Authorization vulnerability that coul… | |
| CVE-2026-19139 | Medium | 0.1% | 7.4 | Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 a… | |
| CVE-2026-76259 | Medium | 0.1% | 8.8 | In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, … | |
| CVE-2026-0294 | Medium | 0.1% | 7.8 | A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Acce… | |
| CVE-2026-78915 | Medium | 0.1% | 7.5 | Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.… | |
| CVE-2026-11241 | Medium | 0.1% | 8.0 | Insufficient validation of untrusted input in Cast in Google Chrome prior to 149… | |
| CVE-2026-17862 | Medium | 0.1% | 7.8 | Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 all… | |
| CVE-2026-17863 | Medium | 0.1% | 7.8 | Inappropriate implementation in Browser in Google Chrome on Windows prior to 151… | |
| CVE-2026-8036 | Medium | 0.1% | 7.1 | Improper input validation in NI-PAL may allow a local authenticated user to acce… | |
| CVE-2026-87509 | Medium | 0.1% | 8.1 | Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0… | |
| CVE-2026-11269 | Medium | 0.1% | 7.1 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-2123 | Medium | 0.1% | 7.8 | A security audit identified a privilege escalation vulnerability in Operations A… | |
| CVE-2026-8035 | Medium | 0.1% | 7.1 | Improper input validation in the NI-PAL kernel driver may allow a local authenti… |