microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-68886 | Low | 0.5% | 5.5 | Use after free in Windows Network Connection Broker allows an authorized attacke… | |
| CVE-2026-69315 | Low | 0.5% | 5.5 | Exposure of sensitive system information to an unauthorized control sphere in Wi… | |
| CVE-2026-50419 | Low | 0.5% | 3.3 | Exposure of sensitive information to an unauthorized actor in Windows Kernel all… | |
| CVE-2026-68873 | Low | 0.5% | 5.5 | Insertion of sensitive information into log file in Windows Program Compatibilit… | |
| CVE-2026-69339 | Low | 0.5% | 5.5 | Exposure of sensitive system information to an unauthorized control sphere in Wi… | |
| CVE-2026-69351 | Low | 0.5% | 5.5 | Exposure of private personal information to an unauthorized actor in Windows Uni… | |
| CVE-2026-69862 | Low | 0.5% | 5.5 | Out-of-bounds read in Windows Wireless Wide Area Network Service allows an autho… | |
| CVE-2026-73008 | Low | 0.5% | 5.5 | Exposure of private personal information to an unauthorized actor in Windows Bio… | |
| CVE-2026-61350 | Low | 0.4% | 4.6 | Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose inf… | |
| CVE-2026-69548 | Low | 0.4% | 4.6 | Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to d… | |
| CVE-2026-78508 | Low | 0.4% | 4.6 | Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to d… | |
| CVE-2026-68797 | Low | 0.4% | 5.5 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2026-20935 | Low | 0.4% | 6.2 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enc… | |
| CVE-2026-49180 | Low | 0.4% | 5.5 | Improper link resolution before file access ('link following') in Universal Plug… | |
| CVE-2026-49177 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose i… | |
| CVE-2026-78451 | Low | 0.4% | 6.8 | Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows… | |
| CVE-2026-49168 | Low | 0.4% | 6.8 | Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauth… | |
| CVE-2026-50298 | Low | 0.4% | 6.8 | Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized a… | |
| CVE-2026-50299 | Low | 0.4% | 6.8 | Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauth… | |
| CVE-2026-50492 | Low | 0.4% | 6.8 | Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an una… | |
| CVE-2026-50668 | Low | 0.4% | 6.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to el… | |
| CVE-2026-54123 | Low | 0.4% | 5.5 | Exposure of sensitive information to an unauthorized actor in Microsoft Defender… | |
| CVE-2026-54132 | Low | 0.4% | 6.8 | Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to … | |
| CVE-2026-62917 | Low | 0.4% | 4.6 | Improper input validation in Microsoft Office SharePoint allows an authorized at… | |
| CVE-2026-45485 | Low | 0.4% | 3.3 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclo… | |
| CVE-2026-69469 | Low | 0.4% | 6.6 | Integer overflow or wraparound in Windows USB Audio Class driver (usbaudio.sys) … | |
| CVE-2026-20962 | Low | 0.4% | 4.4 | Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) al… | |
| CVE-2026-70348 | Low | 0.4% | 5.5 | Improper link resolution before file access ('link following') in Windows Manage… | |
| CVE-2024-21362 | Low | 0.4% | 5.5 | Windows Kernel Security Feature Bypass Vulnerability | |
| CVE-2026-45595 | Low | 0.4% | 5.4 | Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unautho… | |
| CVE-2024-21381 | Low | 0.4% | 6.8 | Microsoft Azure Active Directory B2C Spoofing Vulnerability | |
| CVE-2026-45655 | Low | 0.4% | 5.3 | Protection mechanism failure in Windows BitLocker allows an unauthorized attacke… | |
| CVE-2026-58643 | Low | 0.4% | 6.1 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-64897 | Low | 0.4% | 4.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-64902 | Low | 0.4% | 4.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-64916 | Low | 0.4% | 4.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-64922 | Low | 0.4% | 4.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-79285 | Low | 0.4% | 6.5 | Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.79… | |
| CVE-2026-81387 | Low | 0.4% | 5.5 | Exposure of sensitive system information to an unauthorized control sphere in Mi… | |
| CVE-2026-50377 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate pr… | |
| CVE-2026-62699 | Low | 0.4% | 6.8 | Heap-based buffer overflow in Windows Universal Disk Format File System Driver (… | |
| CVE-2026-71348 | Low | 0.4% | 6.8 | Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attac… | |
| CVE-2026-50420 | Low | 0.4% | 6.2 | Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclo… | |
| CVE-2026-69490 | Low | 0.4% | 6.8 | Out-of-bounds read in Windows USB Mass Storage Class Driver allows an unauthoriz… | |
| CVE-2026-69566 | Low | 0.4% | 6.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-58547 | Low | 0.4% | 5.5 | Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an autho… | |
| CVE-2026-66326 | Low | 0.4% | 6.5 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized … | |
| CVE-2026-40422 | Low | 0.4% | 5.5 | Use of uninitialized resource in Windows File Explorer allows an authorized atta… | |
| CVE-2026-42906 | Low | 0.4% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Shell allo… | |
| CVE-2026-42970 | Low | 0.4% | 5.5 | Exposure of sensitive information to an unauthorized actor in Windows Push Notif… |