microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2023-21693 | Low | 1.4% | 5.7 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulner… | |
| CVE-2021-24104 | Low | 1.4% | 4.6 | Microsoft SharePoint Server Spoofing Vulnerability | |
| CVE-2026-20847 | Low | 1.4% | 6.5 | Exposure of sensitive information to an unauthorized actor in Windows Shell allo… | |
| CVE-2021-27075 | Low | 1.4% | 6.8 | Azure Virtual Machine Information Disclosure Vulnerability | |
| CVE-2022-42343 | Low | 1.4% | 6.5 | Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected … | |
| CVE-2026-45585 | Low | 1.4% | 6.8 | Microsoft is aware of a security feature bypass vulnerability in Windows publicl… | |
| CVE-2023-38158 | Low | 1.3% | 3.1 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | |
| CVE-2026-63516 | Low | 1.3% | 6.5 | Deserialization of untrusted data in Microsoft Office SharePoint allows an autho… | |
| CVE-2024-20679 | Low | 1.3% | 6.5 | Azure Stack Hub Spoofing Vulnerability | |
| CVE-2021-36959 | Low | 1.3% | 5.5 | Windows Authenticode Spoofing Vulnerability | |
| CVE-2020-1075 | Low | 1.3% | 5.5 | An information disclosure vulnerability exists when Windows Subsystem for Linux … | |
| CVE-2021-42308 | Low | 1.3% | 3.1 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | |
| CVE-2021-43220 | Low | 1.3% | 3.1 | Microsoft Edge for iOS Spoofing Vulnerability | |
| CVE-2026-62912 | Low | 1.3% | 6.5 | Deserialization of untrusted data in Microsoft Exchange Server allows an authori… | |
| CVE-2021-36931 | Low | 1.3% | 4.4 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | |
| CVE-2021-36962 | Low | 1.3% | 5.5 | Windows Installer Information Disclosure Vulnerability | |
| CVE-2020-1072 | Low | 1.3% | 5.5 | An information disclosure vulnerability exists when the Windows kernel improperl… | |
| CVE-2020-1116 | Low | 1.3% | 5.5 | An information disclosure vulnerability exists when the Windows Client Server Ru… | |
| CVE-2024-26196 | Low | 1.2% | 4.3 | Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability | |
| CVE-2024-43487 | Low | 1.2% | 6.5 | Windows Mark of the Web Security Feature Bypass Vulnerability | |
| CVE-2021-38641 | Low | 1.2% | 6.1 | Microsoft Edge for Android Spoofing Vulnerability | |
| CVE-2021-38642 | Low | 1.2% | 6.1 | Microsoft Edge for iOS Spoofing Vulnerability | |
| CVE-2023-21720 | Low | 1.2% | 5.3 | Microsoft Edge (Chromium-based) Tampering Vulnerability | |
| CVE-2021-34532 | Low | 1.2% | 5.5 | ASP.NET Core and Visual Studio Information Disclosure Vulnerability | |
| CVE-2021-26892 | Low | 1.2% | 6.2 | Windows Extensible Firmware Interface Security Feature Bypass Vulnerability | |
| CVE-2024-38222 | Low | 1.2% | 6.5 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | |
| CVE-2021-27074 | Low | 1.2% | 6.2 | Azure Sphere Unsigned Code Execution Vulnerability | |
| CVE-2026-44806 | Low | 1.2% | 5.3 | Missing release of memory after effective lifetime in Windows Cryptographic Serv… | |
| CVE-2022-41066 | Low | 1.2% | 4.4 | Microsoft Dynamics Business Central Information Disclosure Vulnerability | |
| CVE-2021-43221 | Low | 1.1% | 4.2 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| CVE-2026-20812 | Low | 1.1% | 6.5 | Improper input validation in Windows LDAP - Lightweight Directory Access Protoco… | |
| CVE-2026-49799 | Low | 1.1% | 6.5 | Uncontrolled resource consumption in Windows Local Security Authority Subsystem … | |
| CVE-2026-50366 | Low | 1.1% | 6.5 | Null pointer dereference in Active Directory Domain Services allows an authorize… | |
| CVE-2026-56168 | Low | 1.1% | 6.5 | Null pointer dereference in Windows SMB Server allows an authorized attacker to … | |
| CVE-2026-57976 | Low | 1.1% | 6.5 | Null pointer dereference in Active Directory Domain Services allows an authorize… | |
| CVE-2026-69497 | Low | 1.1% | 6.5 | Missing release of memory after effective lifetime in Windows DHCP Server allows… | |
| CVE-2026-69839 | Low | 1.1% | 6.5 | Uncaught exception in Windows iSCSI Target Service allows an authorized attacker… | |
| CVE-2021-26886 | Low | 1.1% | 6.1 | User Profile Service Denial of Service Vulnerability | |
| CVE-2021-42301 | Low | 1.1% | 3.3 | Azure RTOS Information Disclosure Vulnerability | |
| CVE-2023-21699 | Low | 1.1% | 5.3 | Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulne… | |
| CVE-2024-43482 | Low | 1.1% | 6.5 | Microsoft Outlook for iOS Information Disclosure Vulnerability | |
| CVE-2026-69374 | Low | 1.1% | 6.5 | Allocation of resources without limits or throttling in Windows SMB Server allow… | |
| CVE-2020-1076 | Low | 1.1% | 5.5 | A denial of service vulnerability exists when Windows improperly handles objects… | |
| CVE-2020-1084 | Low | 1.1% | 5.5 | A Denial Of Service vulnerability exists when Connected User Experiences and Tel… | |
| CVE-2020-1123 | Low | 1.1% | 5.5 | A denial of service vulnerability exists when Connected User Experiences and Tel… | |
| CVE-2020-1131 | Low | 1.1% | 5.5 | An elevation of privilege vulnerability exists when the Windows State Repository… | |
| CVE-2026-21265 | Low | 1.1% | 6.4 | Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These … | |
| CVE-2021-36930 | Low | 1.1% | 5.3 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | |
| CVE-2021-40440 | Low | 1.1% | 5.4 | Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | |
| CVE-2021-36961 | Low | 1.1% | 5.5 | Windows Installer Denial of Service Vulnerability |