microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-87554 | Medium | 0.1% | 8.1 | Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.… | |
| CVE-2026-78892 | Medium | 0.1% | 7.1 | Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 15… | |
| CVE-2026-84334 | Medium | 0.1% | 8.1 | Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 15… | |
| CVE-2026-11103 | Medium | 0.1% | 7.8 | Inappropriate implementation in Installer in Google Chrome on Windows prior to 1… | |
| CVE-2026-11115 | Medium | 0.1% | 7.3 | Use after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 all… | |
| CVE-2026-87457 | Medium | 0.1% | 8.1 | Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 … | |
| CVE-2026-87467 | Medium | 0.1% | 8.1 | Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 … | |
| CVE-2026-50508 | Low | 8.7% | 6.5 | Exposure of sensitive information to an unauthorized actor in Windows NTLM allow… | |
| CVE-2021-42305 | Low | 7.9% | 6.5 | Microsoft Exchange Server Spoofing Vulnerability | |
| CVE-2026-42824 | Low | 7.6% | 6.5 | Improper neutralization of special elements used in a command ('command injectio… | |
| CVE-2020-1113 | Low | 6.1% | 5.3 | A security feature bypass vulnerability exists in Microsoft Windows when the Tas… | |
| CVE-2021-34519 | Low | 6.1% | 5.3 | Microsoft SharePoint Server Information Disclosure Vulnerability | |
| CVE-2020-1179 | Low | 5.1% | 6.5 | An information disclosure vulnerability exists when the Windows GDI component im… | |
| CVE-2026-50507 | Low | 5.0% | 6.8 | Missing authentication for critical function in Windows BitLocker allows an unau… | |
| CVE-2021-41368 | Low | 4.9% | 6.1 | Microsoft Access Remote Code Execution Vulnerability | |
| CVE-2024-38258 | Low | 4.7% | 6.5 | Windows Remote Desktop Licensing Service Information Disclosure Vulnerability | |
| CVE-2020-0963 | Low | 4.6% | 5.5 | An information disclosure vulnerability exists when the Windows GDI component im… | |
| CVE-2019-11049 | Low | 4.2% | 6.5 | In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom h… | |
| CVE-2020-1106 | Low | 4.0% | 6.1 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Serv… | |
| CVE-2021-41351 | Low | 3.9% | 4.3 | Microsoft Edge (Chrome based) Spoofing on IE Mode | |
| CVE-2021-42284 | Low | 3.7% | 6.8 | Windows Hyper-V Denial of Service Vulnerability | |
| CVE-2022-41099 | Low | 3.6% | 4.6 | BitLocker Security Feature Bypass Vulnerability | |
| CVE-2021-34444 | Low | 3.5% | 6.5 | Windows DNS Server Denial of Service Vulnerability | |
| CVE-2026-33829 | Low | 3.4% | 4.3 | Exposure of sensitive information to an unauthorized actor in Windows Snipping T… | |
| CVE-2021-33757 | Low | 3.4% | 5.3 | Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnera… | |
| CVE-2021-33764 | Low | 3.4% | 5.9 | Windows Key Distribution Center Information Disclosure Vulnerability | |
| CVE-2021-34507 | Low | 3.2% | 6.5 | Windows Remote Assistance Information Disclosure Vulnerability | |
| CVE-2021-36929 | Low | 3.2% | 6.3 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | |
| CVE-2021-40448 | Low | 3.2% | 6.3 | Microsoft Accessibility Insights for Android Information Disclosure Vulnerabilit… | |
| CVE-2021-33755 | Low | 3.1% | 6.3 | Windows Hyper-V Denial of Service Vulnerability | |
| CVE-2021-27066 | Low | 3.0% | 4.3 | Windows Admin Center Security Feature Bypass Vulnerability | |
| CVE-2021-27052 | Low | 2.9% | 5.3 | Microsoft SharePoint Server Information Disclosure Vulnerability | |
| CVE-2021-38669 | Low | 2.9% | 6.4 | Microsoft Edge (Chromium-based) Tampering Vulnerability | |
| CVE-2021-26439 | Low | 2.9% | 4.6 | Microsoft Edge for Android Information Disclosure Vulnerability | |
| CVE-2021-33745 | Low | 2.8% | 6.5 | Windows DNS Server Denial of Service Vulnerability | |
| CVE-2021-34499 | Low | 2.8% | 6.5 | Windows DNS Server Denial of Service Vulnerability | |
| CVE-2021-33783 | Low | 2.8% | 6.5 | Windows SMB Information Disclosure Vulnerability | |
| CVE-2021-26436 | Low | 2.7% | 6.1 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | |
| CVE-2023-23382 | Low | 2.7% | 6.5 | Azure Machine Learning Compute Instance Information Disclosure Vulnerability | |
| CVE-2021-38629 | Low | 2.7% | 6.5 | Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerabili… | |
| CVE-2021-34500 | Low | 2.6% | 6.3 | Windows Kernel Memory Information Disclosure Vulnerability | |
| CVE-2023-38157 | Low | 2.5% | 6.5 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | |
| CVE-2020-1173 | Low | 2.5% | 6.8 | A spoofing vulnerability exists in Microsoft Power BI Report Server in the way i… | |
| CVE-2024-38230 | Low | 2.4% | 6.5 | Windows Standards-Based Storage Management Service Denial of Service Vulnerabili… | |
| CVE-2020-9666 | Low | 2.4% | 5.5 | Adobe Campaign Classic before 20.2 have an out-of-bounds read vulnerability. Suc… | |
| CVE-2020-1055 | Low | 2.4% | 5.5 | A cross-site-scripting (XSS) vulnerability exists when Active Directory Federati… | |
| CVE-2020-1103 | Low | 2.4% | 6.5 | An information disclosure vulnerability exists where certain modes of the search… | |
| CVE-2021-26437 | Low | 2.3% | 5.5 | Visual Studio Code Spoofing Vulnerability | |
| CVE-2021-42279 | Low | 2.3% | 4.2 | Chakra Scripting Engine Memory Corruption Vulnerability | |
| CVE-2021-33782 | Low | 2.2% | 5.5 | Windows Authenticode Spoofing Vulnerability |