VulnSea

Microsoft has 2,953 CVEs on record between 2013 and 2026. Disclosure cadence is accelerating: 2136 in the last 90 days against 414 in the 90 before. The busiest recent month was September 2026 with 1005. The median CVSS is 7.8 (high), with 178 rated critical. 3% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 113 days (91 cases). The dominant weakness classes are CWE-122 (585) and CWE-416 (512). Most affected products: windows_10_1607 (644), Windows 10 Version 1607 (481), Microsoft 365 Apps for Enterprise (209).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
3% vs 1% corpus
Median CVSS
7.8
Publish → KEV
113 d median(91)
Last 90 days
2136 prev 414

Products

  • windows_10_1607 644
  • Windows 10 Version 1607 481
  • Microsoft 365 Apps for Enterprise 209
  • windows_10 122
  • 365_apps 115
  • windows_10_1809 106
2953
Total CVEs
178
Critical
91
CISA KEV
92
Exploited

microsoft vulnerabilities

CVEs affecting microsoft, newest first. Open any entry for full detail, references, and exploit status.

2953 CVEsRSS

CVE-2023-36566Medium· 6.5
2y ago

Microsoft Common Data Model SDK Denial of Service Vulnerability

Microsoft Common Data Model SDK Denial of Service Vulnerability

▾ SunlitMicrosoft · Microsoft.CommonDataModel.ObjectModelEPSS 2.8%via OSV
CVE-2023-23376High· 7.8CISA KEV0day
3y ago

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Windows Common Log File System Driver Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 11%via NVD
CVE-2022-37969High· 7.8CISA KEV0dayPoC
4y ago

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Windows Common Log File System Driver Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 28%via NVD
CVE-2022-30190High· 7.8CISA KEV0dayPoC
4y ago

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the c…

▾ Abyssalmicrosoft · windows_10_1507EPSS 99%via NVD
CVE-2022-21882High· 7.0CISA KEV0dayPoC
4y ago

Win32k Elevation of Privilege Vulnerability

Win32k Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1809EPSS 59%via NVD
CVE-2021-43226High· 7.8CISA KEVPoC
4y ago

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Windows Common Log File System Driver Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 3.1%via NVD
CVE-2021-43890High· 7.1CISA KEV0day
4y ago

We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows

We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malw…

▾ Abyssalmicrosoft · app_installerEPSS 10%via NVD
CVE-2021-42321High· 8.8CISA KEVPoC
4y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · exchange_serverEPSS 92%via NVD
CVE-2021-42292High· 7.8CISA KEVPoC
4y ago

Microsoft Excel Security Feature Bypass Vulnerability

Microsoft Excel Security Feature Bypass Vulnerability

▾ Abyssalmicrosoft · 365_appsEPSS 43%via NVD
CVE-2021-41379Medium· 5.5CISA KEV0day
4y ago

Windows Installer Elevation of Privilege Vulnerability

Windows Installer Elevation of Privilege Vulnerability

▾ Midnightmicrosoft · windows_10_1507EPSS 19%via NVD
CVE-2021-42287High· 7.5CISA KEVPoC
4y ago

Active Directory Domain Services Elevation of Privilege Vulnerability

Active Directory Domain Services Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_server_2008EPSS 77%via NVD
CVE-2021-42278High· 7.5CISA KEVPoC
4y ago

Active Directory Domain Services Elevation of Privilege Vulnerability

Active Directory Domain Services Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_server_2004EPSS 73%via NVD
CVE-2021-40444High· 8.8CISA KEV0dayPoC
5y ago

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft …

▾ Abyssalmicrosoft · windows_10_1507EPSS 97%via NVD
CVE-2021-38649High· 7.0CISA KEV
5y ago

Open Management Infrastructure Elevation of Privilege Vulnerability

Open Management Infrastructure Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · azure_automation_state_configurationEPSS 2.9%via NVD
CVE-2021-38648High· 7.8CISA KEVPoC
5y ago

Open Management Infrastructure Elevation of Privilege Vulnerability

Open Management Infrastructure Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · azure_automation_state_configurationEPSS 11%via NVD
CVE-2021-38647Critical· 9.8CISA KEVPoC
5y ago

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

▾ Hadalmicrosoft · azure_automation_state_configurationEPSS 100%via NVD
CVE-2021-38646High· 7.8CISA KEV
5y ago

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

▾ Abyssalmicrosoft · 365_appsEPSS 8.0%via NVD
CVE-2021-38645High· 7.8CISA KEV
5y ago

Open Management Infrastructure Elevation of Privilege Vulnerability

Open Management Infrastructure Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · azure_automation_state_configurationEPSS 2.7%via NVD
CVE-2021-36955High· 7.8CISA KEVPoC
5y ago

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Windows Common Log File System Driver Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 4.0%via NVD
CVE-2021-36948High· 7.8CISA KEV0day
5y ago

Windows Update Medic Service Elevation of Privilege Vulnerability

Windows Update Medic Service Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1809EPSS 23%via NVD
CVE-2021-36942High· 7.5CISA KEVPoC
5y ago

Windows LSA Spoofing Vulnerability

Windows LSA Spoofing Vulnerability

▾ Abyssalmicrosoft · windows_server_2004EPSS 66%via NVD
CVE-2021-34486High· 7.8CISA KEVPoC
5y ago

Windows Event Tracing Elevation of Privilege Vulnerability

Windows Event Tracing Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1809EPSS 9.3%via NVD
CVE-2021-34484High· 7.8CISA KEV
5y ago

Windows User Profile Service Elevation of Privilege Vulnerability

Windows User Profile Service Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 22%via NVD
CVE-2021-36934High· 7.8CISA KEVPoC
5y ago

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnera…

▾ Abyssalmicrosoft · windows_10_1809EPSS 67%via NVD
CVE-2021-34448Medium· 6.8CISA KEV0day
5y ago

Scripting Engine Memory Corruption Vulnerability

Scripting Engine Memory Corruption Vulnerability

▾ Midnightmicrosoft · windows_10_1507EPSS 40%via NVD
CVE-2021-34447Medium· 6.8
5y ago

Windows MSHTML Platform Remote Code Execution Vulnerability

Windows MSHTML Platform Remote Code Execution Vulnerability

▾ Sunlitmicrosoft · windows_10EPSS 2.0%via NVD
CVE-2021-34446High· 8.0
5y ago

Windows HTML Platforms Security Feature Bypass Vulnerability

Windows HTML Platforms Security Feature Bypass Vulnerability

▾ Twilightmicrosoft · windows_10EPSS 2.0%via NVD
CVE-2021-34445High· 7.8
5y ago

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

▾ Twilightmicrosoft · windows_10EPSS 0.64%via NVD
CVE-2021-34444Medium· 6.5
5y ago

Windows DNS Server Denial of Service Vulnerability

Windows DNS Server Denial of Service Vulnerability

▾ Sunlitmicrosoft · windows_server_2008EPSS 3.5%via NVD
CVE-2021-34442High· 8.8
5y ago

Windows DNS Server Remote Code Execution Vulnerability

Windows DNS Server Remote Code Execution Vulnerability

▾ Twilightmicrosoft · windows_server_2008EPSS 3.1%via NVD
microsoft vulnerabilities (CVEs) — page 91 · VulnSea