microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-70328 | Low | 0.9% | 6.5 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2021-26428 | Low | 0.9% | 4.4 | Azure Sphere Information Disclosure Vulnerability | |
| CVE-2021-43211 | Low | 0.9% | 5.5 | Windows 10 Update Assistant Elevation of Privilege Vulnerability | |
| CVE-2026-68874 | Low | 0.8% | 5.7 | Out-of-bounds read in Windows Program Compatibility Assistant Service allows an … | |
| CVE-2026-69349 | Low | 0.8% | 5.7 | Use of uninitialized resource in Windows Management Instrumentation allows an au… | |
| CVE-2026-69507 | Low | 0.8% | 5.7 | Insertion of sensitive information into externally-accessible file or directory … | |
| CVE-2026-56185 | Low | 0.8% | 6.5 | Improper authentication in Windows Admin Center allows an authorized attacker to… | |
| CVE-2026-69683 | Low | 0.8% | 6.5 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an auth… | |
| CVE-2026-58639 | Low | 0.8% | 6.5 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an auth… | |
| CVE-2026-69803 | Low | 0.8% | 5.9 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to dis… | |
| CVE-2026-69929 | Low | 0.8% | 5.9 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to dis… | |
| CVE-2026-70124 | Low | 0.8% | 5.9 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to dis… | |
| CVE-2026-69930 | Low | 0.8% | 5.9 | Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to dis… | |
| CVE-2026-61921 | Low | 0.8% | 6.5 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to d… | |
| CVE-2026-61924 | Low | 0.8% | 6.5 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to d… | |
| CVE-2021-38632 | Low | 0.8% | 5.7 | Windows BitLocker Security Feature Bypass Vulnerability | |
| CVE-2024-26188 | Low | 0.8% | 4.3 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | |
| CVE-2021-36943 | Low | 0.8% | 4.0 | Azure CycleCloud Elevation of Privilege Vulnerability | |
| CVE-2026-42907 | Low | 0.8% | 6.5 | Exposure of sensitive information to an unauthorized actor in Windows Shell allo… | |
| CVE-2021-34466 | Low | 0.8% | 5.7 | Windows Hello Security Feature Bypass Vulnerability | |
| CVE-2021-41373 | Low | 0.8% | 5.5 | FSLogix Information Disclosure Vulnerability | |
| CVE-2026-69372 | Low | 0.8% | 5.7 | Out-of-bounds read in Windows Network File System allows an authorized attacker … | |
| CVE-2021-31961 | Low | 0.8% | 6.1 | Windows InstallService Elevation of Privilege Vulnerability | |
| CVE-2023-21567 | Low | 0.8% | 5.6 | Visual Studio Denial of Service Vulnerability | |
| CVE-2026-42914 | Low | 0.8% | 5.3 | Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny ser… | |
| CVE-2026-66303 | Low | 0.8% | 6.5 | Null pointer dereference in Skype for Business allows an authorized attacker to … | |
| CVE-2026-67633 | Low | 0.8% | 6.5 | Out-of-bounds read in SQL Server allows an authorized attacker to deny service o… | |
| CVE-2022-41064 | Low | 0.8% | 5.8 | .NET Framework Information Disclosure Vulnerability | |
| CVE-2021-33744 | Low | 0.8% | 5.3 | Windows Secure Kernel Mode Security Feature Bypass Vulnerability | |
| CVE-2022-41060 | Low | 0.8% | 5.5 | Microsoft Word Information Disclosure Vulnerability | |
| CVE-2022-41104 | Low | 0.8% | 5.5 | Microsoft Excel Security Feature Bypass Vulnerability | |
| CVE-2022-41105 | Low | 0.8% | 5.5 | Microsoft Excel Information Disclosure Vulnerability | |
| CVE-2026-47287 | Low | 0.8% | 6.5 | Relative path traversal in Visual Studio Code allows an unauthorized attacker to… | |
| CVE-2026-68785 | Low | 0.8% | 4.9 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execut… | |
| CVE-2026-62902 | Low | 0.8% | 6.5 | Inclusion of functionality from untrusted control sphere in .NET allows an unaut… | |
| CVE-2026-40375 | Low | 0.8% | 6.5 | Missing authorization in Dynamics Business Central allows an authorized attacker… | |
| CVE-2022-41098 | Low | 0.8% | 5.5 | Windows GDI+ Information Disclosure Vulnerability | |
| CVE-2024-43489 | Low | 0.8% | 6.5 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | |
| CVE-2026-47655 | Low | 0.8% | 6.5 | Exposure of sensitive information to an unauthorized actor in Microsoft Graph al… | |
| CVE-2026-81377 | Low | 0.8% | 6.5 | Improper limitation of a pathname to a restricted directory ('path traversal') i… | |
| CVE-2023-35389 | Low | 0.8% | 6.5 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | |
| CVE-2024-21340 | Low | 0.8% | 4.6 | Windows Kernel Information Disclosure Vulnerability | |
| CVE-2026-20834 | Low | 0.8% | 4.6 | Absolute path traversal in Windows Shell allows an unauthorized attacker to perf… | |
| CVE-2026-73029 | Low | 0.7% | 6.5 | Buffer over-read in SQL Server allows an authorized attacker to disclose informa… | |
| CVE-2026-67369 | Low | 0.7% | 6.5 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose infor… | |
| CVE-2026-67393 | Low | 0.7% | 6.5 | Buffer over-read in SQL Server allows an authorized attacker to disclose informa… | |
| CVE-2026-68777 | Low | 0.7% | 6.5 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose infor… | |
| CVE-2026-68778 | Low | 0.7% | 6.5 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose infor… | |
| CVE-2026-68780 | Low | 0.7% | 6.5 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose infor… | |
| CVE-2026-47644 | Low | 0.7% | 6.5 | Improper neutralization of special elements in output used by a downstream compo… |