microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-34346 | Low | 0.3% | 5.5 | Cleartext transmission of sensitive information in Windows Ancillary Function Dr… | |
| CVE-2026-49174 | Low | 0.3% | 6.1 | Missing authentication for critical function in Microsoft Windows DNS allows an … | |
| CVE-2026-50303 | Low | 0.3% | 5.5 | Use of a cryptographic primitive with a risky implementation in Windows Key Guar… | |
| CVE-2026-48302 | Low | 0.3% | 6.2 | CAI Content Credentials is affected by an Improper Input Validation vulnerabilit… | |
| CVE-2026-69425 | Low | 0.3% | 4.7 | Improper link resolution before file access ('link following') in Windows NTFS a… | |
| CVE-2026-50418 | Low | 0.3% | 5.1 | Improper access control in Windows System allows an unauthorized attacker to byp… | |
| CVE-2022-41086 | Low | 0.3% | 6.4 | Windows Group Policy Elevation of Privilege Vulnerability | |
| CVE-2026-48353 | Low | 0.3% | 5.5 | CAI Content Credentials is affected by an Improper Input Validation vulnerabilit… | |
| CVE-2026-79177 | Low | 0.3% | 6.5 | Incorrect authorization in Media in Google Chrome on on Windows prior to 152.0.7… | |
| CVE-2026-47969 | Low | 0.3% | 5.5 | Audition is affected by an out-of-bounds read vulnerability that could lead to d… | |
| CVE-2026-5903 | Low | 0.3% | 6.5 | Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a… | |
| CVE-2026-7340 | Low | 0.3% | 4.3 | Integer overflow in ANGLE in Google Chrome on Windows prior to 147.0.7727.138 al… | |
| CVE-2026-9124 | Low | 0.3% | 5.3 | Insufficient validation of untrusted input in Input in Google Chrome on prior to… | |
| CVE-2026-62883 | Low | 0.3% | 6.7 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate… | |
| CVE-2026-65795 | Low | 0.3% | 6.7 | Relative path traversal in Windows DNS allows an authorized attacker to elevate … | |
| CVE-2026-65797 | Low | 0.3% | 6.7 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate… | |
| CVE-2026-65798 | Low | 0.3% | 6.7 | Numeric truncation error in Windows DNS allows an authorized attacker to elevate… | |
| CVE-2026-17992 | Low | 0.3% | 6.5 | Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 all… | |
| CVE-2026-48296 | Low | 0.3% | 6.2 | CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound)… | |
| CVE-2026-48298 | Low | 0.3% | 6.2 | CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound)… | |
| CVE-2026-48357 | Low | 0.3% | 6.2 | CAI Content Credentials is affected by an Uncontrolled Resource Consumption vuln… | |
| CVE-2026-62775 | Low | 0.3% | 5.5 | Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs… | |
| CVE-2026-5888 | Low | 0.3% | 6.5 | Uninitialized Use in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a… | |
| CVE-2026-69267 | Low | 0.3% | 6.5 | Insufficient granularity of access control in Windows Connected User Experiences… | |
| CVE-2026-69878 | Low | 0.3% | 6.4 | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker … | |
| CVE-2026-71338 | Low | 0.3% | 6.4 | Double free in Windows Failover Cluster allows an authorized attacker to elevate… | |
| CVE-2026-62757 | Low | 0.3% | 5.3 | Improper verification of cryptographic signature in Windows Schannel allows an u… | |
| CVE-2026-65799 | Low | 0.3% | 6.7 | Integer overflow or wraparound in Windows DNS allows an authorized attacker to e… | |
| CVE-2026-11039 | Low | 0.3% | 6.5 | Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-11057 | Low | 0.3% | 6.5 | Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-11067 | Low | 0.3% | 6.5 | Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-11087 | Low | 0.3% | 6.5 | Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11089 | Low | 0.3% | 6.5 | Uninitialized Use in Media in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11090 | Low | 0.3% | 6.5 | Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11101 | Low | 0.3% | 6.5 | Uninitialized Use in Dawn in Google Chrome on Windows prior to 149.0.7827.53 all… | |
| CVE-2026-11104 | Low | 0.3% | 6.5 | Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11109 | Low | 0.3% | 6.5 | Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11110 | Low | 0.3% | 6.5 | Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11123 | Low | 0.3% | 6.5 | Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11137 | Low | 0.3% | 6.5 | Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11138 | Low | 0.3% | 6.5 | Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11141 | Low | 0.3% | 6.5 | Uninitialized Use in Audio in Google Chrome prior to 149.0.7827.53 allowed a rem… | |
| CVE-2026-11268 | Low | 0.3% | 6.5 | Uninitialized Use in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 al… | |
| CVE-2026-11182 | Low | 0.2% | 6.5 | Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-5876 | Low | 0.2% | 6.5 | Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7… | |
| CVE-2026-79253 | Low | 0.2% | 6.5 | Improper input validation in Network in Google Chrome on on Windows prior to 152… | |
| CVE-2026-87454 | Low | 0.2% | 6.5 | Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.801… | |
| CVE-2026-9953 | Low | 0.2% | 6.5 | Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a r… | |
| CVE-2026-17846 | Low | 0.2% | 6.5 | Inappropriate implementation in Media in Google Chrome on Windows prior to 151.0… | |
| CVE-2026-58543 | Low | 0.2% | 6.3 | Concurrent execution using shared resource with improper synchronization ('race … |