microsoft
3,712 known vulnerabilities affecting microsoft products.
Products
windows_server_2019 1452
windows_server_2016 1310
windows_server_2022 1272
windows_server_2025 1131
windows_10_1809 1131
windows_11_24h2 1111
windows_11_25h2 1081
windows_10_22h2 1066
windows_10_21h2 1061
windows_11_26h1 1009
windows 990
windows_10_1607 980
windows_server_2012 977
windows_11_23h2 761
windows_10 343
windows_server_2008 326
365_apps 277
office_2021 225
office_2024 225
office_2019 217
windows_8.1 192
microsoft_365 185
windows_rt_8.1 170
windows_7 169
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-34521 | Medium | 2.4% | 7.8 | Raw Image Extension Remote Code Execution Vulnerability | |
| CVE-2022-38023 | Medium | 2.4% | 8.1 | Netlogon RPC Elevation of Privilege Vulnerability | |
| CVE-2021-42316 | Medium | 2.3% | 8.8 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | |
| CVE-2021-34518 | Medium | 2.3% | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | |
| CVE-2024-38236 | Medium | 2.3% | 7.5 | DHCP Server Service Denial of Service Vulnerability | |
| CVE-2021-34503 | Medium | 2.3% | 7.8 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | |
| CVE-2021-36937 | Medium | 2.3% | 7.8 | Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability | |
| CVE-2021-38644 | Medium | 2.3% | 7.8 | Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability | |
| CVE-2021-38660 | Medium | 2.3% | 7.8 | Microsoft Office Graphics Remote Code Execution Vulnerability | |
| CVE-2021-38661 | Medium | 2.3% | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | |
| CVE-2021-40442 | Medium | 2.3% | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | |
| CVE-2026-42989 | Medium | 2.3% | 7.8 | Improper link resolution before file access ('link following') in Winlogon allow… | |
| CVE-2021-34508 | Medium | 2.2% | 8.8 | Windows Kernel Remote Code Execution Vulnerability | |
| CVE-2021-34525 | Medium | 2.2% | 8.8 | Windows DNS Server Remote Code Execution Vulnerability | |
| CVE-2021-34452 | Medium | 2.2% | 7.8 | Microsoft Word Remote Code Execution Vulnerability | |
| CVE-2021-36941 | Medium | 2.2% | 7.8 | Microsoft Word Remote Code Execution Vulnerability | |
| CVE-2020-1125 | Medium | 2.2% | 7.0 | An elevation of privilege vulnerability exists when the Windows Runtime improper… | |
| CVE-2020-1149 | Medium | 2.2% | 7.0 | An elevation of privilege vulnerability exists when the Windows Runtime improper… | |
| CVE-2020-1151 | Medium | 2.2% | 7.0 | An elevation of privilege vulnerability exists when the Windows Runtime improper… | |
| CVE-2020-1164 | Medium | 2.2% | 7.0 | An elevation of privilege vulnerability exists when the Windows Runtime improper… | |
| CVE-2021-34438 | Medium | 2.2% | 7.8 | Windows Font Driver Host Remote Code Execution Vulnerability | |
| CVE-2021-34441 | Medium | 2.2% | 7.8 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | |
| CVE-2024-21400 | Medium | 2.2% | 9.0 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege… | |
| CVE-2024-37966 | Medium | 2.2% | 7.1 | Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | |
| CVE-2024-21348 | Medium | 2.2% | 7.5 | Internet Connection Sharing (ICS) Denial of Service Vulnerability | |
| CVE-2021-34474 | Medium | 2.2% | 8.0 | Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability | |
| CVE-2023-29328 | Medium | 2.2% | 8.8 | Microsoft Teams Remote Code Execution Vulnerability | |
| CVE-2026-33116 | Medium | 2.1% | 7.5 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, … | |
| CVE-2021-34468 | Medium | 2.1% | 7.1 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| CVE-2021-33786 | Medium | 2.1% | 8.1 | Windows LSA Security Feature Bypass Vulnerability | |
| CVE-2026-61930 | Medium | 2.1% | 7.8 | Heap-based buffer overflow in Windows Kernel allows an authorized attacker to el… | |
| CVE-2026-62741 | Medium | 2.1% | 7.8 | Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized … | |
| CVE-2021-26882 | Medium | 2.1% | 7.8 | Remote Access API Elevation of Privilege Vulnerability | |
| CVE-2022-41056 | Medium | 2.1% | 7.5 | Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability | |
| CVE-2021-42275 | Medium | 2.1% | 8.8 | Microsoft COM for Windows Remote Code Execution Vulnerability | |
| CVE-2023-35390 | Medium | 2.1% | 7.8 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2022-41053 | Medium | 2.1% | 7.5 | Windows Kerberos Denial of Service Vulnerability | |
| CVE-2022-41058 | Medium | 2.1% | 7.5 | Windows Network Address Translation (NAT) Denial of Service Vulnerability | |
| CVE-2023-36912 | Medium | 2.1% | 7.5 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | |
| CVE-2023-36741 | Medium | 2.1% | 8.3 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | |
| CVE-2021-34446 | Medium | 2.0% | 8.0 | Windows HTML Platforms Security Feature Bypass Vulnerability | |
| CVE-2026-42905 | Medium | 2.0% | 7.8 | Use after free in Windows DWM Core Library allows an authorized attacker to elev… | |
| CVE-2026-42986 | Medium | 2.0% | 7.8 | Use after free in Microsoft Graphics Component allows an authorized attacker to … | |
| CVE-2023-21709 | Medium | 2.0% | 9.8 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| CVE-2023-29330 | Medium | 2.0% | 8.8 | Microsoft Teams Remote Code Execution Vulnerability | |
| CVE-2021-33746 | Medium | 2.0% | 8.0 | Windows DNS Server Remote Code Execution Vulnerability | |
| CVE-2023-36787 | Medium | 2.0% | 8.8 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | |
| CVE-2023-38172 | Medium | 2.0% | 7.5 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | |
| CVE-2021-33754 | Medium | 2.0% | 8.0 | Windows DNS Server Remote Code Execution Vulnerability | |
| CVE-2026-62783 | Medium | 2.0% | 7.8 | Heap-based buffer overflow in Windows Remote Access Connection Manager allows an… |