microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-55015 | Low | 0.5% | 5.5 | Uncontrolled search path element in Windows Remote Help allows an authorized att… | |
| CVE-2026-69406 | Low | 0.5% | 5.5 | Exposure of sensitive system information to an unauthorized control sphere in Wi… | |
| CVE-2026-57095 | Low | 0.5% | 6.2 | Exposure of sensitive information to an unauthorized actor in Windows Win32K all… | |
| CVE-2026-20839 | Low | 0.5% | 5.5 | Improper access control in Windows Client-Side Caching (CSC) Service allows an a… | |
| CVE-2026-17622 | Low | 0.5% | 6.5 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacke… | |
| CVE-2026-19299 | Low | 0.5% | 6.5 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke… | |
| CVE-2026-19302 | Low | 0.5% | 6.5 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke… | |
| CVE-2026-61920 | Low | 0.5% | 6.6 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-62915 | Low | 0.5% | 6.5 | Missing authorization in Microsoft Exchange Server allows an authorized attacker… | |
| CVE-2024-21304 | Low | 0.5% | 4.1 | Trusted Compute Base Elevation of Privilege Vulnerability | |
| CVE-2026-20936 | Low | 0.5% | 4.3 | Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose inf… | |
| CVE-2026-50661 | Low | 0.5% | 6.1 | Protection mechanism failure in Windows BitLocker allows an unauthorized attacke… | |
| CVE-2026-62715 | Low | 0.5% | 6.5 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthor… | |
| CVE-2026-62718 | Low | 0.5% | 6.5 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthor… | |
| CVE-2026-62742 | Low | 0.5% | 6.5 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthor… | |
| CVE-2026-33842 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explo… | |
| CVE-2026-34328 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Audio Serv… | |
| CVE-2026-34349 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Media allo… | |
| CVE-2026-41087 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explo… | |
| CVE-2026-50316 | Low | 0.5% | 5.5 | Insertion of sensitive information into log file in Windows Kernel allows an aut… | |
| CVE-2026-50334 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Notificati… | |
| CVE-2026-50339 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Push Notif… | |
| CVE-2026-50350 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Trusted Ru… | |
| CVE-2026-50352 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Cryptograp… | |
| CVE-2026-50389 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explo… | |
| CVE-2026-50394 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Media allo… | |
| CVE-2026-50430 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Push Notif… | |
| CVE-2026-50431 | Low | 0.5% | 5.5 | Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnera… | |
| CVE-2026-50434 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Push Notif… | |
| CVE-2026-50442 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explo… | |
| CVE-2026-50456 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explo… | |
| CVE-2026-50473 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows File Explo… | |
| CVE-2026-50483 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Microsoft Graphics… | |
| CVE-2026-50681 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Cryptograp… | |
| CVE-2026-56184 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Win32K all… | |
| CVE-2026-64918 | Low | 0.5% | 6.5 | Insufficiently protected credentials in Microsoft Office allows an unauthorized … | |
| CVE-2026-72971 | Low | 0.5% | 5.5 | Improper link resolution before file access ('link following') in Windows Contai… | |
| CVE-2023-36769 | Low | 0.5% | 4.6 | Microsoft OneNote Spoofing Vulnerability | |
| CVE-2026-49794 | Low | 0.5% | 4.6 | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an un… | |
| CVE-2026-62714 | Low | 0.5% | 6.5 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthor… | |
| CVE-2026-62716 | Low | 0.5% | 6.5 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthor… | |
| CVE-2026-62720 | Low | 0.5% | 6.5 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthor… | |
| CVE-2026-78452 | Low | 0.5% | 4.6 | Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unautho… | |
| CVE-2026-70314 | Low | 0.5% | 5.5 | Improper input validation in Microsoft Office allows an unauthorized attacker to… | |
| CVE-2023-21687 | Low | 0.5% | 5.5 | HTTP.sys Information Disclosure Vulnerability | |
| CVE-2026-44821 | Low | 0.5% | 5.5 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclo… | |
| CVE-2026-3482 | Low | 0.5% | 5.3 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.… | |
| CVE-2026-42971 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Push Notif… | |
| CVE-2026-42972 | Low | 0.5% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Hyper-V al… | |
| CVE-2026-63530 | Low | 0.5% | 5.5 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to d… |