Where
AND
-Infinity
0

Vendor Risk Score

See how microsoft compares to other vendors in security performance

View Risk Score →

Software

microsoft windows operating system
1634
microsoft windows
1565
microsoft windows server 2016
1411
microsoft windows server 2019
1223
microsoft edge
942
microsoft windows server
908
microsoft windows 10
812
microsoft windows server 2022
807
microsoft windows 7
791
microsoft edge (chromium-based)
719
microsoft windows server 2012 r2
542
microsoft windows 11
538
microsoft windows rt
513
microsoft windows 10 22h2
465
microsoft windows server 2022 23h2
464
microsoft windows 10 21h2
462
microsoft windows 10 1809
448
microsoft windows server 2025
447
microsoft windows server 2012
444
microsoft windows 11 24h2
428
microsoft windows server 2022, 23h2 edition
401
microsoft windows 11 23h2
386
microsoft windows 10 1607
373
microsoft windows server 2008
359
microsoft windows xp
353
microsoft cbl2 kernel 5.15.186.1-1
344
microsoft windows vista
314
microsoft windows 11 22h2
304
microsoft edge beta
292
microsoft internet explorer
263
microsoft windows 10 1507
227
microsoft windows 11 25h2
222
microsoft windows 8.1
213
microsoft azl3 kernel 6.6.117.1-1
204
microsoft azl3 kernel 6.6.96.2-2
193
microsoft windows 2000
182
microsoft windows server 2008 r2
180
microsoft azl3 kernel 6.6.112.1-2
162
microsoft office
161
microsoft windows server 2008 r2 for itanium-based systems
160
microsoft azl3 kernel 6.6.92.2-1
159
microsoft azl3 kernel 6.6.104.2-4
156
microsoft windows 11 26h1
145
microsoft sharepoint enterprise server 2016
144
microsoft windows nt
129
microsoft azl3 kernel 6.6.96.2-1
126
microsoft azl3 kernel 6.6.47.1-1
123
microsoft sharepoint server 2010
120
microsoft windows server 2003
120
microsoft azl3 kernel 6.6.139.1-1
116

Microsoft EdgeMicrosoft Edge (Chromium-based) Spoofing Vulnerability

Risk 34
Severity
5.4
First published (updated )

Microsoft GraphMicrosoft Graph Information Disclosure Vulnerability

Risk 38
Severity
6.5
First published (updated )

Nlnet Labs UnboundDegradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration

Risk 37
Severity
5.9
First published (updated )

Nlnet Labs UnboundPossible heap buffer overflow when validator canonicalizes RDATA that contains domain name

Risk 34
Severity
4.8
First published (updated )

Nlnet Labs UnboundRemote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2

Risk 37
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Nlnet Labs UnboundPacket of death for a DNSCrypt misconfigured Unbound

Risk 37
Severity
5.9
First published (updated )

Nlnet Labs Unbound'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash

Risk 37
Severity
5.9
First published (updated )

Nlnet Labs UnboundMemory corruption could lead to crash and denial of service

Risk 37
Severity
5.9
First published (updated )

Nlnet Labs UnboundPossible cache poisoning attack by mapping source port population per thread

Risk 71
Severity
5.7
First published (updated )

Nlnet Labs UnboundAttacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush

Risk 28
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Nlnet Labs UnboundBOGUS configured primary hostname accepted for XFR in auth/rpz zones

Risk 48
Severity
6.5
First published (updated )

Nlnet Labs Unbound'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL

Risk 30
Severity
6.3
First published (updated )

Nlnet Labs UnboundPossible heap use-after-free in an error path when a DoT forwarded query is jostled out

Risk 37
Severity
5.9
First published (updated )

Nlnet Labs Unbound'max-global-quota' reset by DNSSEC validation restarts

Risk 28
Severity
5.3
First published (updated )

Nlnet Labs UnboundLibunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated

Risk 37
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Nlnet Labs UnboundAssertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments

Risk 37
Severity
5.9
First published (updated )

CoreDNS CoreDNSCoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record

Risk 27
Severity
5.3
First published (updated )

Microsoft WindowsA potential missing authentication vulnerability could allow a local privileged attacker to use WMI …

Risk 34
Severity
6.7
First published (updated )

Microsoft UFOMicrosoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing authenticated session-squatting denial of service

Risk 38
Severity
6.5
First published (updated )

Microsoft UFOMicrosoft UFO: Missing Authorization in DEVICE_INFO_REQUEST Allows a DEVICE Client to Read Another Device's system_info

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Microsoft Windows Admin CenterWindows Admin Center Spoofing Vulnerability

Risk 38
Severity
6.1
First published (updated )

Microsoft SharePoint ServerMicrosoft SharePoint Server Spoofing Vulnerability

Risk 34
Severity
5.4
First published (updated )

Microsoft Microsoft EdgeMicrosoft Edge (Chromium-based) Tampering Vulnerability

Risk 34
Severity
5.4
First published (updated )

CAI Content CredentialsCAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)

Risk 36
Severity
6.2
First published (updated )

CAI Content CredentialsCAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)

Risk 36
Severity
6.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CAI Content CredentialsCAI Content Credentials | Improper Input Validation (CWE-20)

Risk 45
Severity
6.8
First published (updated )

CAI Content CredentialsCAI Content Credentials | Improper Input Validation (CWE-20)

Risk 36
Severity
6.2
First published (updated )

CAI Content CredentialsCAI Content Credentials | Integer Overflow or Wraparound (CWE-190)

Risk 36
Severity
6.2
First published (updated )

CAI Content CredentialsCAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)

Risk 36
Severity
6.2
First published (updated )

CAI Content CredentialsCAI Content Credentials | Improper Input Validation (CWE-20)

Risk 31
Severity
5.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203