microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-5896 | Low | 0.2% | 6.1 | Policy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote … | |
| CVE-2026-71441 | Low | 0.2% | 5.5 | Illustrator is affected by an out-of-bounds read vulnerability that could lead t… | |
| CVE-2026-82001 | Low | 0.2% | 5.5 | Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability… | |
| CVE-2026-11126 | Low | 0.2% | 4.3 | Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53… | |
| CVE-2026-11219 | Low | 0.2% | 4.3 | Inappropriate implementation in Navigation in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-11228 | Low | 0.2% | 4.3 | Inappropriate implementation in File Input in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-11286 | Low | 0.2% | 4.3 | Insufficient validation of untrusted input in Wallet in Google Chrome prior to 1… | |
| CVE-2026-11294 | Low | 0.2% | 4.3 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.5… | |
| CVE-2026-11300 | Low | 0.2% | 4.3 | Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827… | |
| CVE-2026-47961 | Low | 0.2% | 5.5 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a… | |
| CVE-2026-5897 | Low | 0.2% | 4.3 | Incorrect security UI in Downloads in Google Chrome prior to 147.0.7727.55 allow… | |
| CVE-2026-11187 | Low | 0.2% | 6.3 | Inappropriate implementation in Glic in Google Chrome prior to 149.0.7827.53 all… | |
| CVE-2026-81997 | Low | 0.2% | 6.3 | Acrobat Reader is affected by an Incorrect Authorization vulnerability that coul… | |
| CVE-2026-17900 | Low | 0.2% | 4.3 | Inappropriate implementation in Enterprise in Google Chrome on Windows prior to … | |
| CVE-2026-11217 | Low | 0.2% | 6.5 | Inappropriate implementation in Fenced Frames in Google Chrome prior to 149.0.78… | |
| CVE-2026-5893 | Low | 0.2% | 6.8 | Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to … | |
| CVE-2026-11221 | Low | 0.1% | 4.3 | Insufficient validation of untrusted input in PointerLock in Google Chrome prior… | |
| CVE-2026-11243 | Low | 0.1% | 5.4 | Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.5… | |
| CVE-2026-11253 | Low | 0.1% | 4.3 | Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827… | |
| CVE-2026-11181 | Low | 0.1% | 6.3 | Inappropriate implementation in Media Session in Google Chrome prior to 149.0.78… | |
| CVE-2026-47909 | Low | 0.1% | 6.3 | Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Input … | |
| CVE-2026-11232 | Low | 0.1% | 5.4 | Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.5… | |
| CVE-2026-21350 | Low | 0.1% | 5.5 | After Effects versions 25.6 and earlier are affected by a NULL Pointer Dereferen… | |
| CVE-2026-27268 | Low | 0.1% | 5.5 | Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-of-bounds R… | |
| CVE-2026-9986 | Low | 0.1% | 4.2 | Insufficient validation of untrusted input in OptimizationGuide in Google Chrome… | |
| CVE-2026-27285 | Low | 0.1% | 5.5 | InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based … | |
| CVE-2026-57978 | Low | 0.1% | 5.4 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorize… | |
| CVE-2026-66316 | Low | 0.1% | 5.4 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorize… | |
| CVE-2026-66317 | Low | 0.1% | 5.4 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorize… | |
| CVE-2026-27270 | Low | 0.1% | 5.5 | Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-of-bounds R… | |
| CVE-2026-7572 | Low | 0.1% | 4.4 | An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array f… | |
| CVE-2026-9991 | Low | 0.1% | 3.1 | Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0… | |
| CVE-2026-11267 | Low | 0.1% | 4.3 | Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.78… | |
| CVE-2026-5901 | Low | 0.1% | 6.5 | Insufficient policy enforcement in DevTools in Google Chrome prior to 147.0.7727… | |
| CVE-2026-11212 | Low | 0.1% | 4.3 | Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827… | |
| CVE-2026-47910 | Low | 0.1% | 6.3 | Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Autho… | |
| CVE-2026-9959 | Low | 0.1% | 3.1 | Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a rem… | |
| CVE-2026-11062 | Low | 0.1% | 4.3 | Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.78… | |
| CVE-2026-5899 | Low | 0.1% | 6.1 | Insufficient policy enforcement in History Navigation in Google Chrome prior to … | |
| CVE-2026-79084 | Low | 0.1% | 4.3 | Inadequate encryption strength in Notifications in Google Chrome on on Windows p… | |
| CVE-2026-11309 | Low | 0.1% | 4.3 | Insufficient policy enforcement in History in Google Chrome prior to 149.0.7827.… | |
| CVE-2026-0292 | Low | 0.1% | 6.0 | An authentication bypass vulnerability in the network driver of Palo Alto Networ… | |
| CVE-2026-34704 | Low | 0.1% | 5.5 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointe… | |
| CVE-2026-9979 | Low | 0.1% | 5.0 | Insufficient validation of untrusted input in Input in Google Chrome prior to 14… | |
| CVE-2026-9980 | Low | 0.1% | 5.0 | Insufficient validation of untrusted input in Printing in Google Chrome prior to… | |
| CVE-2026-18622 | Low | 0.1% | 4.7 | Foxit PDF Editor/Reader inconsistently alerts users when signature fields are ab… | |
| CVE-2026-19696 | Low | 0.1% | 6.6 | Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 … | |
| CVE-2026-11157 | Low | 0.1% | 5.4 | Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowe… | |
| CVE-2026-80159 | Low | 0.1% | 4.0 | Acrobat Reader is affected by an Untrusted Search Path vulnerability that could … | |
| CVE-2026-7351 | Low | 0.1% | 3.1 | Race in MHTML in Google Chrome prior to 147.0.7727.138 allowed an attacker who c… |