microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-11096 | Low | 0.2% | 6.5 | Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a r… | |
| CVE-2026-11105 | Low | 0.2% | 6.5 | Insufficient validation of untrusted input in WebUI in Google Chrome prior to 14… | |
| CVE-2026-5864 | Low | 0.2% | 4.3 | Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed… | |
| CVE-2026-5869 | Low | 0.2% | 4.3 | Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a … | |
| CVE-2026-68849 | Low | 0.2% | 4.7 | Out-of-bounds read in Windows Bluetooth Port Driver allows an authorized attacke… | |
| CVE-2026-34614 | Low | 0.2% | 6.1 | Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cro… | |
| CVE-2026-9935 | Low | 0.2% | 4.3 | Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a re… | |
| CVE-2026-11284 | Low | 0.2% | 6.5 | Side-channel information leakage in PerformanceAPIs in Google Chrome prior to 14… | |
| CVE-2026-5885 | Low | 0.2% | 6.5 | Insufficient validation of untrusted input in WebML in Google Chrome on Windows … | |
| CVE-2026-58638 | Low | 0.2% | 6.0 | Missing cryptographic step in Windows Boot Loader allows an authorized attacker … | |
| CVE-2026-62828 | Low | 0.2% | 5.4 | Improper input validation in Microsoft Edge for Android allows an unauthorized a… | |
| CVE-2026-65804 | Low | 0.2% | 6.1 | Improper control of generation of code ('code injection') in Microsoft Edge (Chr… | |
| CVE-2026-69642 | Low | 0.2% | 6.5 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-70339 | Low | 0.2% | 5.4 | Access of resource using incompatible type ('type confusion') in Microsoft Edge … | |
| CVE-2026-78979 | Low | 0.2% | 4.3 | Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 all… | |
| CVE-2026-11098 | Low | 0.2% | 5.3 | Insufficient validation of untrusted input in GPU in Google Chrome prior to 149.… | |
| CVE-2026-17858 | Low | 0.2% | 4.3 | Uninitialized Use in WebNN in Google Chrome on Windows prior to 151.0.7922.72 al… | |
| CVE-2026-56178 | Low | 0.2% | 5.5 | Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endp… | |
| CVE-2026-17631 | Low | 0.2% | 5.0 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacke… | |
| CVE-2026-10916 | Low | 0.2% | 6.1 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to… | |
| CVE-2026-11073 | Low | 0.2% | 6.5 | Use after free in WebGL in Google Chrome prior to 149.0.7827.53 allowed a remote… | |
| CVE-2026-11075 | Low | 0.2% | 6.5 | Out of bounds read in V8 in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-11093 | Low | 0.2% | 6.5 | Inappropriate implementation in Printing in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-11121 | Low | 0.2% | 6.5 | Insufficient validation of untrusted input in Skia in Google Chrome prior to 149… | |
| CVE-2026-11128 | Low | 0.2% | 6.5 | Inappropriate implementation in Web Share in Google Chrome prior to 149.0.7827.5… | |
| CVE-2026-11140 | Low | 0.2% | 6.5 | Out of bounds read in Chromecast in Google Chrome prior to 149.0.7827.53 allowed… | |
| CVE-2026-11168 | Low | 0.2% | 6.5 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-11180 | Low | 0.2% | 6.5 | Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-11206 | Low | 0.2% | 6.5 | Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 149.0… | |
| CVE-2026-11208 | Low | 0.2% | 6.5 | Use after free in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remot… | |
| CVE-2026-11209 | Low | 0.2% | 6.5 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.5… | |
| CVE-2026-11271 | Low | 0.2% | 6.5 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.5… | |
| CVE-2026-79126 | Low | 0.2% | 5.9 | Incorrect provision of specified functionality in Proxy in Google Chrome on on W… | |
| CVE-2026-11196 | Low | 0.2% | 6.5 | Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remote a… | |
| CVE-2026-34694 | Low | 0.2% | 4.8 | Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are af… | |
| CVE-2026-11107 | Low | 0.2% | 4.3 | Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.5… | |
| CVE-2026-11023 | Low | 0.2% | 6.5 | Inappropriate implementation in WebAppInstalls in Google Chrome prior to 149.0.7… | |
| CVE-2026-11653 | Low | 0.2% | 6.5 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-11658 | Low | 0.2% | 6.5 | Insufficient validation of untrusted input in Extensions in Google Chrome prior … | |
| CVE-2026-79123 | Low | 0.2% | 6.5 | Improper input validation in NTP Footer in Google Chrome on on Windows prior to … | |
| CVE-2026-79243 | Low | 0.2% | 6.5 | Improper input validation in ReadingList in Google Chrome on on Windows prior to… | |
| CVE-2026-9115 | Low | 0.2% | 4.3 | Insufficient policy enforcement in Service Worker in Google Chrome on prior to 1… | |
| CVE-2026-66325 | Low | 0.2% | 6.1 | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an … | |
| CVE-2026-21278 | Low | 0.2% | 5.5 | InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Out-of-bou… | |
| CVE-2026-11020 | Low | 0.2% | 6.5 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-33103 | Low | 0.2% | 5.5 | Improper access control in Microsoft Dynamics 365 (on-premises) allows an author… | |
| CVE-2026-58616 | Low | 0.2% | 4.4 | Concurrent execution using shared resource with improper synchronization ('race … | |
| CVE-2026-9882 | Low | 0.2% | 6.5 | Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a rem… | |
| CVE-2026-11159 | Low | 0.2% | 4.3 | Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remo… | |
| CVE-2026-9113 | Low | 0.2% | 4.3 | Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowe… |