microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-65794 | Low | 0.7% | 6.5 | Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclo… | |
| CVE-2026-69550 | Low | 0.7% | 6.5 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to d… | |
| CVE-2026-65813 | Low | 0.7% | 6.5 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an author… | |
| CVE-2024-21377 | Low | 0.6% | 5.5 | Windows DNS Information Disclosure Vulnerability | |
| CVE-2026-20862 | Low | 0.6% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Management… | |
| CVE-2026-69637 | Low | 0.6% | 5.7 | Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny … | |
| CVE-2026-69679 | Low | 0.6% | 5.7 | Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny … | |
| CVE-2026-58279 | Low | 0.6% | 6.5 | Missing authorization in Azure CycleCloud allows an authorized attacker to eleva… | |
| CVE-2021-34493 | Low | 0.6% | 6.7 | Windows Partition Management Driver Elevation of Privilege Vulnerability | |
| CVE-2026-45455 | Low | 0.6% | 3.3 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2023-36889 | Low | 0.6% | 5.5 | Windows Group Policy Security Feature Bypass Vulnerability | |
| CVE-2026-62839 | Low | 0.6% | 6.5 | Insufficiently protected credentials in Microsoft Office SharePoint allows an au… | |
| CVE-2026-45650 | Low | 0.6% | 4.3 | User interface (ui) misrepresentation of critical information in Microsoft Bing … | |
| CVE-2021-42300 | Low | 0.6% | 6.0 | Azure Sphere Tampering Vulnerability | |
| CVE-2026-62882 | Low | 0.6% | 4.3 | Insufficiently protected credentials in Microsoft Office Outlook allows an unaut… | |
| CVE-2026-66308 | Low | 0.6% | 6.5 | Out-of-bounds read in Skype for Business allows an authorized attacker to deny s… | |
| CVE-2026-67641 | Low | 0.6% | 6.5 | Integer overflow or wraparound in SQL Server allows an authorized attacker to de… | |
| CVE-2023-21572 | Low | 0.6% | 6.5 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| CVE-2026-78446 | Low | 0.6% | 5.3 | Use after free in Windows Distributed File System (DFS) allows an authorized att… | |
| CVE-2023-21570 | Low | 0.6% | 5.4 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| CVE-2023-21571 | Low | 0.6% | 5.4 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| CVE-2023-21573 | Low | 0.6% | 5.4 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| CVE-2026-68898 | Low | 0.6% | 6.5 | Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny serv… | |
| CVE-2026-69297 | Low | 0.6% | 6.5 | Storing passwords in a recoverable format in Windows DHCP Server allows an autho… | |
| CVE-2026-81381 | Low | 0.6% | 6.5 | Insufficiently protected credentials in GitHub Copilot and Visual Studio Code al… | |
| CVE-2023-21714 | Low | 0.6% | 5.5 | Microsoft Office Information Disclosure Vulnerability | |
| CVE-2026-20851 | Low | 0.6% | 6.2 | Out-of-bounds read in Capability Access Management Service (camsvc) allows an un… | |
| CVE-2024-21423 | Low | 0.6% | 4.8 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | |
| CVE-2026-62826 | Low | 0.6% | 4.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2022-41055 | Low | 0.6% | 5.5 | Windows Human Interface Device Information Disclosure Vulnerability | |
| CVE-2026-65806 | Low | 0.6% | 6.5 | Missing authorization in Azure CycleCloud allows an authorized attacker to discl… | |
| CVE-2023-36914 | Low | 0.6% | 5.5 | Windows Smart Card Resource Management Server Security Feature Bypass Vulnerabil… | |
| CVE-2026-69904 | Low | 0.6% | 3.5 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an auth… | |
| CVE-2026-66312 | Low | 0.6% | 6.5 | Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacke… | |
| CVE-2026-62750 | Low | 0.6% | 6.5 | Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized … | |
| CVE-2026-20829 | Low | 0.6% | 5.5 | Out-of-bounds read in Windows TPM allows an authorized attacker to disclose info… | |
| CVE-2026-20835 | Low | 0.6% | 5.5 | Out-of-bounds read in Capability Access Management Service (camsvc) allows an au… | |
| CVE-2026-69405 | Low | 0.6% | 5.7 | Missing release of memory after effective lifetime in Windows DHCP Server allows… | |
| CVE-2026-69416 | Low | 0.6% | 5.7 | Buffer over-read in Windows DHCP Server allows an authorized attacker to deny se… | |
| CVE-2024-20695 | Low | 0.6% | 5.7 | Skype for Business Information Disclosure Vulnerability | |
| CVE-2021-42319 | Low | 0.6% | 4.7 | Visual Studio Elevation of Privilege Vulnerability | |
| CVE-2023-21694 | Low | 0.6% | 6.8 | Windows Fax Service Remote Code Execution Vulnerability | |
| CVE-2026-50426 | Low | 0.6% | 6.8 | Relative path traversal in DNS Server allows an authorized attacker to execute c… | |
| CVE-2026-66798 | Low | 0.6% | 4.3 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacke… | |
| CVE-2026-49159 | Low | 0.6% | 6.5 | Exposure of sensitive information to an unauthorized actor in Microsoft Graph al… | |
| CVE-2026-67645 | Low | 0.6% | 6.5 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose infor… | |
| CVE-2026-67648 | Low | 0.6% | 6.5 | Use of uninitialized resource in SQL Server allows an authorized attacker to dis… | |
| CVE-2026-68776 | Low | 0.6% | 6.5 | Use of uninitialized resource in SQL Server allows an authorized attacker to dis… | |
| CVE-2026-68779 | Low | 0.6% | 6.5 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose infor… | |
| CVE-2024-21339 | Low | 0.6% | 6.4 | Windows USB Generic Parent Driver Remote Code Execution Vulnerability |