Where
-Infinity
0

Vendor Risk Score

See how microsoft compares to other vendors in security performance

View Risk Score →

Software

microsoft windows operating system
6769
microsoft windows
6118
microsoft windows server 2016
5580
microsoft windows server 2019
5154
microsoft windows server
3561
microsoft windows server 2022
3400
microsoft windows 10
3321
microsoft windows 7
3092
microsoft edge
2529
microsoft windows server 2012 r2
2301
microsoft windows 11
2077
microsoft windows rt
1995
microsoft edge (chromium-based)
1960
microsoft windows server 2012
1834
microsoft windows 10 1809
1745
microsoft windows 10 21h2
1740
microsoft windows server 2025
1735
microsoft windows 10 22h2
1729
microsoft windows server 2022 23h2
1724
microsoft windows 11 24h2
1655
microsoft windows 10 1607
1478
microsoft windows server 2022, 23h2 edition
1431
microsoft windows server 2008
1422
microsoft windows 11 23h2
1417
microsoft windows xp
1356
microsoft windows vista
1353
microsoft windows 8.1
1078
microsoft office
1074
microsoft edge beta
1028
microsoft windows 11 25h2
1014
microsoft windows 11 22h2
1003
microsoft internet explorer
915
microsoft windows 10 1507
833
microsoft windows server 2008 r2 for itanium-based systems
831
microsoft windows 11 26h1
727
microsoft windows server 2008 r2
690
microsoft windows 2000
635
microsoft cbl2 kernel 5.15.186.1-1
562
microsoft 365 apps for enterprise
532
microsoft windows rt 8.1
513
microsoft windows server 2003
491
microsoft 365 apps
443
microsoft azl3 kernel 6.6.96.2-2
378
microsoft windows 11 21h2
368
microsoft office ltsc 2021 for 64-bit editions
354
microsoft office ltsc 2021 for 32-bit editions
353
microsoft windows 2003 server
346
microsoft sharepoint enterprise server 2016
345
microsoft office 2019 for 32-bit editions
342
microsoft office 2019 for 64-bit editions
342

Microsoft EdgeMicrosoft Edge (Chromium-based) Information Disclosure Vulnerability

Risk 42
Severity
7.4
First published (updated )

Microsoft EdgeMicrosoft Edge (Chromium-based) Spoofing Vulnerability

Risk 34
Severity
5.4
First published (updated )

Microsoft EdgeMicrosoft Edge (Chromium-based) Information Disclosure Vulnerability

Risk 42
Severity
7.4
First published (updated )

Microsoft Azure DNSAzure DNS Elevation of Privilege Vulnerability

Risk 73
Severity
10
First published (updated )

Microsoft Azure API Management (APIM)Azure API Management (APIM) Remote Code Execution Vulnerability

Risk 65
Severity
8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Microsoft Azure AI SearchAzure AI Search Elevation of Privilege Vulnerability

Risk 55
Severity
8.5
First published (updated )

Microsoft Azure Red Hat OpenShift (ARO)Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability

Risk 72
Severity
9.1
First published (updated )

Microsoft GraphMicrosoft Graph Information Disclosure Vulnerability

Risk 38
Severity
6.5
First published (updated )

Microsoft Azure Key VaultAzure Key Vault Elevation of Privilege Vulnerability

Risk 73
Severity
10
First published (updated )

Microsoft 365 CopilotMicrosoft M365 Copilot Remote Code Execution Vulnerability

Risk 82
Severity
9.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Microsoft Surface Management ServicesMicrosoft Surface Remote Code Execution Vulnerability

Risk 82
Severity
9.9
First published (updated )

Microsoft AccountMicrosoft Account Remote Code Execution Vulnerability

Risk 86
Severity
9.8
First published (updated )

Microsoft Azure App Service for LinuxAzure App Service on Azure Stack Hub Elevation of Privilege Vulnerability

Risk 73
Severity
10
First published (updated )

Microsoft Exchange OnlineMicrosoft Exchange Online Tampering Vulnerability

Risk 87
Severity
10
First published (updated )

Microsoft Purview Data GovernanceData Quality Elevation of Privilege Vulnerability

Risk 87
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Microsoft Online ServicesAzure Portal Information Disclosure Vulnerability

Risk 61
Severity
9.3
First published (updated )

Microsoft Azure Kubernetes ServiceMicrosoft Azure Kubernetes Service Elevation of Privilege Vulnerability

Risk 87
Severity
10
First published (updated )

CVE-2026-50458: Finding a UAF in the Windows Brokering File System

First published (updated )
Social
reddit

Nlnet Labs UnboundDegradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration

Risk 37
Severity
5.9
First published (updated )

Nlnet Labs UnboundPossible heap buffer overflow when validator canonicalizes RDATA that contains domain name

Risk 34
Severity
4.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Nlnet Labs UnboundRemote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2

Risk 37
Severity
5.9
First published (updated )

Nlnet Labs UnboundPacket of death for a DNSCrypt misconfigured Unbound

Risk 37
Severity
5.9
First published (updated )

Nlnet Labs Unbound'dns-error-reporting: yes' leads to stack buffer overflow

Risk 46
Severity
7.5
First published (updated )

Nlnet Labs Unbound'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash

Risk 37
Severity
5.9
First published (updated )

Nlnet Labs UnboundPrivacy/configuration issue when adding local data in views through 'unbound-control'

Risk 23
Severity
3.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Nlnet Labs UnboundDNS Cookie bypass when combined with proxy-protocol use

Risk 21
Severity
3.7
First published (updated )

Nlnet Labs UnboundMemory corruption could lead to crash and denial of service

Risk 37
Severity
5.9
First published (updated )

Nlnet Labs UnboundPossible cache poisoning attack by mapping source port population per thread

Risk 71
Severity
5.7
First published (updated )

Nlnet Labs UnboundAttacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush

Risk 28
Severity
5.3
First published (updated )

Nlnet Labs UnboundBOGUS configured primary hostname accepted for XFR in auth/rpz zones

Risk 48
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203