microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-69568 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Storage Spaces Controller allows an authorized att… | |
| CVE-2026-69609 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose i… | |
| CVE-2026-69616 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Remote Desktop Services allows an authorized attac… | |
| CVE-2026-69627 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authori… | |
| CVE-2026-69808 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose i… | |
| CVE-2026-71341 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Partition Management Driver allows an authorized a… | |
| CVE-2026-72980 | Low | 0.4% | 4.4 | Uncontrolled search path element in Windows Hello allows an authorized attacker … | |
| CVE-2026-45466 | Low | 0.4% | 3.3 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attac… | |
| CVE-2026-81391 | Low | 0.4% | 5.5 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized a… | |
| CVE-2026-81393 | Low | 0.4% | 5.5 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2026-81399 | Low | 0.4% | 5.5 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to di… | |
| CVE-2026-81400 | Low | 0.4% | 5.5 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2026-81958 | Low | 0.4% | 5.5 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized a… | |
| CVE-2026-42915 | Low | 0.4% | 5.5 | Incorrect calculation of buffer size in Windows VMSwitch allows an authorized at… | |
| CVE-2026-45606 | Low | 0.4% | 5.5 | Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authoriz… | |
| CVE-2026-65785 | Low | 0.4% | 6.5 | Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized … | |
| CVE-2026-68831 | Low | 0.4% | 5.5 | Files or directories accessible to external parties in Windows Defender Firewall… | |
| CVE-2026-45500 | Low | 0.4% | 6.1 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-50475 | Low | 0.4% | 5.5 | Buffer over-read in Windows Kernel allows an authorized attacker to disclose inf… | |
| CVE-2026-70315 | Low | 0.4% | 5.5 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclo… | |
| CVE-2026-70316 | Low | 0.4% | 5.5 | Improper input validation in Microsoft Office PowerPoint allows an unauthorized … | |
| CVE-2026-70319 | Low | 0.4% | 5.5 | Improper input validation in Microsoft Office Word allows an unauthorized attack… | |
| CVE-2026-70320 | Low | 0.4% | 5.5 | Improper input validation in Microsoft Office PowerPoint allows an unauthorized … | |
| CVE-2026-70322 | Low | 0.4% | 5.5 | Improper input validation in Microsoft Office PowerPoint allows an unauthorized … | |
| CVE-2026-70323 | Low | 0.4% | 5.5 | Improper input validation in Microsoft Office allows an unauthorized attacker to… | |
| CVE-2026-70325 | Low | 0.4% | 5.5 | Improper input validation in Microsoft Office PowerPoint allows an unauthorized … | |
| CVE-2026-17790 | Low | 0.4% | 4.3 | Uninitialized Use in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 al… | |
| CVE-2026-61368 | Low | 0.4% | 5.0 | Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to d… | |
| CVE-2026-85875 | Low | 0.4% | 5.5 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2026-39844 | Low | 0.4% | 5.9 | NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath onl… | |
| CVE-2026-45459 | Low | 0.4% | 3.3 | Protection mechanism failure in Microsoft Office Excel allows an unauthorized at… | |
| CVE-2026-45460 | Low | 0.4% | 4.7 | Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose… | |
| CVE-2026-57085 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows Print Spooler Components allows an authorized atta… | |
| CVE-2026-59136 | Low | 0.4% | 5.5 | Use of uninitialized resource in Microsoft COM for Windows allows an authorized … | |
| CVE-2026-69832 | Low | 0.4% | 5.6 | Exposure of sensitive system information to an unauthorized control sphere in Wi… | |
| CVE-2026-45634 | Low | 0.4% | 5.5 | Out-of-bounds read in Windows DHCP Server allows an authorized attacker to discl… | |
| CVE-2026-62745 | Low | 0.4% | 6.5 | Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthor… | |
| CVE-2026-2812 | Low | 0.4% | 5.3 | ArcGIS Server contains an improper authentication vulnerability in an undocument… | |
| CVE-2026-33822 | Low | 0.4% | 6.1 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to d… | |
| CVE-2026-62842 | Low | 0.4% | 5.5 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclo… | |
| CVE-2026-63517 | Low | 0.4% | 5.5 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclo… | |
| CVE-2026-70318 | Low | 0.4% | 5.5 | Improper input validation in Microsoft Office Excel allows an unauthorized attac… | |
| CVE-2026-70317 | Low | 0.4% | 5.5 | Use of uninitialized resource in Microsoft Office allows an unauthorized attacke… | |
| CVE-2026-44805 | Low | 0.4% | 5.5 | Use after free in Windows Network Controller (NC) Host Agent allows an authorize… | |
| CVE-2026-62829 | Low | 0.4% | 4.6 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-68842 | Low | 0.4% | 5.5 | Exposure of sensitive system information to an unauthorized control sphere in Wi… | |
| CVE-2026-49167 | Low | 0.4% | 4.7 | Use after free in Windows Kernel allows an authorized attacker to elevate privil… | |
| CVE-2026-50312 | Low | 0.4% | 4.7 | Use after free in Windows Ancillary Function Driver for WinSock allows an author… | |
| CVE-2026-58545 | Low | 0.4% | 5.5 | Improper access control in Windows Kernel allows an authorized attacker to bypas… | |
| CVE-2026-63524 | Low | 0.3% | 5.5 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclo… |