microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-63528 | Low | 0.3% | 5.5 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to d… | |
| CVE-2026-63529 | Low | 0.3% | 5.5 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclo… | |
| CVE-2026-63531 | Low | 0.3% | 5.5 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to d… | |
| CVE-2026-64899 | Low | 0.3% | 5.5 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclo… | |
| CVE-2026-64917 | Low | 0.3% | 5.5 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to d… | |
| CVE-2026-68799 | Low | 0.3% | 5.5 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized a… | |
| CVE-2026-68802 | Low | 0.3% | 5.5 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2026-68808 | Low | 0.3% | 5.5 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2026-68813 | Low | 0.3% | 5.5 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to … | |
| CVE-2026-45604 | Low | 0.3% | 5.5 | Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an a… | |
| CVE-2026-83991 | Low | 0.3% | 5.5 | Missing authentication for critical function in Windows Cloud Files Mini Filter … | |
| CVE-2026-69294 | Low | 0.3% | 5.5 | Generation of error message containing sensitive information in Microsoft COM fo… | |
| CVE-2026-55000 | Low | 0.3% | 6.4 | Use after free in Windows USB Print Driver allows an unauthorized attacker to el… | |
| CVE-2026-45608 | Low | 0.3% | 6.8 | Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to dis… | |
| CVE-2026-34626 | Low | 0.3% | 6.3 | Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are… | |
| CVE-2026-59130 | Low | 0.3% | 5.6 | No cwe for this issue in AMD Zen allows an authorized attacker to disclose infor… | |
| CVE-2026-9110 | Low | 0.3% | 4.2 | Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.77… | |
| CVE-2026-14470 | Low | 0.3% | 6.5 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to t… | |
| CVE-2026-50302 | Low | 0.3% | 4.2 | Improper certificate validation in Windows Cryptographic Services allows an unau… | |
| CVE-2026-62769 | Low | 0.3% | 6.7 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate… | |
| CVE-2026-62881 | Low | 0.3% | 6.7 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate… | |
| CVE-2026-71339 | Low | 0.3% | 6.7 | Heap-based buffer overflow in Windows Installer allows an authorized attacker to… | |
| CVE-2026-66314 | Low | 0.3% | 6.5 | Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-ba… | |
| CVE-2026-59135 | Low | 0.3% | 5.5 | Weak authentication in Microsoft Windows Search Component allows an authorized a… | |
| CVE-2026-45642 | Low | 0.3% | 3.9 | Improper input validation in Microsoft Azure Attestation service and Device Heal… | |
| CVE-2026-44814 | Low | 0.3% | 5.5 | Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to … | |
| CVE-2026-62708 | Low | 0.3% | 6.4 | Use after free in Windows Kernel allows an unauthorized attacker to elevate priv… | |
| CVE-2026-70304 | Low | 0.3% | 6.7 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to eleva… | |
| CVE-2026-70330 | Low | 0.3% | 6.7 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to eleva… | |
| CVE-2026-62786 | Low | 0.3% | 5.5 | Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose i… | |
| CVE-2026-62793 | Low | 0.3% | 5.5 | Buffer over-read in Windows NTFS allows an authorized attacker to disclose infor… | |
| CVE-2026-62796 | Low | 0.3% | 5.5 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose inf… | |
| CVE-2026-62798 | Low | 0.3% | 5.5 | Untrusted pointer dereference in Windows Win32K allows an authorized attacker to… | |
| CVE-2026-65662 | Low | 0.3% | 5.5 | Out-of-bounds read in Windows GDI allows an authorized attacker to disclose info… | |
| CVE-2026-50310 | Low | 0.3% | 4.7 | Integer overflow or wraparound in Windows Devices Human Interface allows an auth… | |
| CVE-2026-11006 | Low | 0.3% | 6.5 | Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11008 | Low | 0.3% | 6.5 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome pr… | |
| CVE-2026-11013 | Low | 0.3% | 6.5 | Insufficient validation of untrusted input in Network in Google Chrome prior to … | |
| CVE-2026-45501 | Low | 0.3% | 6.5 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an author… | |
| CVE-2026-66806 | Low | 0.3% | 5.5 | Off-by-one error in Microsoft Office Word allows an unauthorized attacker to dis… | |
| CVE-2026-68833 | Low | 0.3% | 6.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-71329 | Low | 0.3% | 6.8 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to ex… | |
| CVE-2026-72999 | Low | 0.3% | 6.8 | Out-of-bounds read in Windows USB Hub Driver allows an unauthorized attacker to … | |
| CVE-2026-77892 | Low | 0.3% | 6.8 | No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to… | |
| CVE-2026-83501 | Low | 0.3% | 5.5 | Out-of-bounds read in Windows Virtualization-Based Security (VBS) Enclave allows… | |
| CVE-2026-50295 | Low | 0.3% | 5.5 | Improper privilege management in Microsoft Windows DNS allows an authorized atta… | |
| CVE-2026-50495 | Low | 0.3% | 6.1 | Improper access control in Microsoft Windows DNS allows an authorized attacker t… | |
| CVE-2026-69554 | Low | 0.3% | 5.5 | Missing authentication for critical function in Microsoft Windows Search Compone… | |
| CVE-2026-2813 | Low | 0.3% | 4.7 | ArcGIS Server contains an input validation weakness in the login redirection wor… | |
| CVE-2026-65784 | Low | 0.3% | 5.5 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose inf… |