microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-81991 | Low | 0.2% | 5.5 | Acrobat Reader is affected by an out-of-bounds read vulnerability that could lea… | |
| CVE-2026-11122 | Low | 0.2% | 6.1 | Inappropriate implementation in Keyboard in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-11186 | Low | 0.2% | 6.1 | Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-11189 | Low | 0.2% | 6.5 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to… | |
| CVE-2026-11222 | Low | 0.2% | 6.5 | Incorrect security UI in Tab Strip in Google Chrome prior to 149.0.7827.53 allow… | |
| CVE-2026-11684 | Low | 0.2% | 3.1 | Insufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-27301 | Low | 0.2% | 5.5 | Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer… | |
| CVE-2026-11238 | Low | 0.2% | 5.9 | Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-5892 | Low | 0.2% | 6.6 | Insufficient policy enforcement in PWAs in Google Chrome prior to 147.0.7727.55 … | |
| CVE-2026-87602 | Low | 0.2% | 4.7 | Out of bounds read in ANGLE in Google Chrome on on Windows prior to 153.0.8010.3… | |
| CVE-2026-11183 | Low | 0.2% | 6.5 | Out of bounds read in GWP-ASan in Google Chrome prior to 149.0.7827.53 allowed a… | |
| CVE-2026-11691 | Low | 0.2% | 3.1 | Insufficient validation of untrusted input in New Tab Page in Google Chrome prio… | |
| CVE-2026-5898 | Low | 0.2% | 4.3 | Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 … | |
| CVE-2026-84329 | Low | 0.2% | 5.3 | Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 15… | |
| CVE-2026-11266 | Low | 0.2% | 4.3 | Inappropriate implementation in SafeBrowsing in Google Chrome prior to 149.0.782… | |
| CVE-2026-66313 | Low | 0.2% | 6.8 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorize… | |
| CVE-2026-11026 | Low | 0.2% | 6.5 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-11383 | Low | 0.2% | 5.4 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Applicati… | |
| CVE-2026-47925 | Low | 0.2% | 5.5 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-5911 | Low | 0.2% | 4.3 | Policy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed … | |
| CVE-2025-36298 | Low | 0.2% | 5.4 | IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2… | |
| CVE-2025-36431 | Low | 0.2% | 5.4 | IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gate… | |
| CVE-2026-11036 | Low | 0.2% | 6.5 | Inappropriate implementation in DOM in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-11081 | Low | 0.2% | 6.5 | Inappropriate implementation in Canvas in Google Chrome prior to 149.0.7827.53 a… | |
| CVE-2026-11190 | Low | 0.2% | 6.5 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-10004 | Low | 0.2% | 6.5 | Insufficient validation of untrusted input in Passwords in Google Chrome prior t… | |
| CVE-2026-11155 | Low | 0.2% | 4.3 | Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-11156 | Low | 0.2% | 4.3 | Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-11161 | Low | 0.2% | 4.3 | Inappropriate implementation in DataTransfer in Google Chrome prior to 149.0.782… | |
| CVE-2026-11216 | Low | 0.2% | 4.3 | Incorrect security UI in File Input in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-5906 | Low | 0.2% | 4.3 | Incorrect security UI in Omnibox in Google Chrome on Android prior to 147.0.7727… | |
| CVE-2026-21358 | Low | 0.2% | 5.5 | InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based … | |
| CVE-2026-11150 | Low | 0.2% | 6.1 | Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allo… | |
| CVE-2026-11273 | Low | 0.2% | 6.1 | Insufficient validation of untrusted input in Omnibox in Google Chrome prior to … | |
| CVE-2026-21319 | Low | 0.2% | 5.5 | After Effects versions 25.6 and earlier are affected by an Out-of-bounds Read vu… | |
| CVE-2026-21332 | Low | 0.2% | 5.5 | InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by an out-of-bou… | |
| CVE-2026-5894 | Low | 0.2% | 4.3 | Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allo… | |
| CVE-2026-5900 | Low | 0.2% | 4.3 | Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a rem… | |
| CVE-2026-11048 | Low | 0.2% | 6.5 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-11184 | Low | 0.2% | 6.3 | Insufficient policy enforcement in Actor in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-11225 | Low | 0.2% | 6.5 | Inappropriate implementation in WebUI in Google Chrome prior to 149.0.7827.53 al… | |
| CVE-2026-11227 | Low | 0.2% | 6.5 | Incorrect security UI in Tab Hover Cards in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-17908 | Low | 0.2% | 5.8 | Insufficient validation of untrusted input in Printing in Google Chrome on Windo… | |
| CVE-2026-5895 | Low | 0.2% | 5.4 | Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 … | |
| CVE-2026-5918 | Low | 0.2% | 4.3 | Inappropriate implementation in Navigation in Google Chrome prior to 147.0.7727.… | |
| CVE-2026-70309 | Low | 0.2% | 5.4 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorize… | |
| CVE-2026-27286 | Low | 0.2% | 5.5 | InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based … | |
| CVE-2026-34662 | Low | 0.2% | 5.5 | Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Der… | |
| CVE-2026-27299 | Low | 0.2% | 6.3 | Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input V… | |
| CVE-2026-27300 | Low | 0.2% | 5.5 | Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Uninit… |