Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

15,270 known vulnerabilities

262
CRITICAL
2,149
HIGH
1,022
MEDIUM
42
LOW

Top Products

windows 1558 windows server 2025 1055 windows 11 24h2 1025 windows 11 25h2 1024 windows server 2022 953 windows 11 26h1 926 windows server 2019 883 windows 10 22h2 875 windows 10 21h2 874 windows 10 1809 871
3,475 CVEs · Page 1/70
6.5
CVE-2026-79253

Improper input validation in Network in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker lev

8.3
CVE-2026-79247

Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had com

6.5
CVE-2026-79243

Improper input validation in ReadingList in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker

8.1
CVE-2026-79194

Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to execute

6.5
CVE-2026-79177

Incorrect authorization in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had

8.3
CVE-2026-79175

Type confusion in Accessibility in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had

7.5
CVE-2026-79139

Improper input validation in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who h

9.6
CVE-2026-79138

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentia

5.9
CVE-2026-79126

Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an

6.5
CVE-2026-79123

Improper input validation in NTP Footer in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker

4.3
CVE-2026-79084

Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote a

8.8
CVE-2026-79048

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentia

9.6
CVE-2026-79019

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentia

9.6
CVE-2026-78989

Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potential

4.3
CVE-2026-78979

Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social

8.8
CVE-2026-78978

Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potential

8.3
CVE-2026-78952

Out of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had

7.5
CVE-2026-78915

Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to poten

9.9
CVE-2026-69851

Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a

10.0
CVE-2026-69836

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

8.6
CVE-2026-69558

Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose

10.0
CVE-2026-69555

Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

8.5
CVE-2026-69543

Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a

8.6
CVE-2026-69519

Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a networ

9.6
CVE-2026-69400

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize

9.9
CVE-2026-68789

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an aut

9.9
CVE-2026-68782

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an aut

8.6
CVE-2026-66800

Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a

9.1
CVE-2026-66309

Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

10.0
CVE-2026-65816

Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a

10.0
CVE-2026-65801

Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges ov

10.0
CVE-2026-65770

Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache

9.3
CVE-2026-62834

Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privil

5.5
CVE-2026-55015

Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.

7.1
CVE-2026-55013

Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locall

8.8
CVE-2026-76259

In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to

6.5
CVE-2026-69550

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

7.5
CVE-2026-19875

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abu

8.4
CVE-2026-76037

Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to

7.8
CVE-2026-69414

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicl

7.8
CVE-2026-50523

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an au

8.3
CVE-2026-72970

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a net

9.1
CVE-2026-19297

IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to

9.4
CVE-2026-14525

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnera

5.7
CVE-2026-10571

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecu

5.4
CVE-2026-70339

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized

6.7
CVE-2026-65680

Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to el

7.7
CVE-2026-48447

Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution

8.6
CVE-2026-48441

Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulne

7.8
CVE-2026-48410

Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 15,270 CVE records in our database, including 470 critical and 10790 high severity vulnerabilities. 30 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 470 critical severity (CVSS 9.0+) and 10790 high severity (CVSS 7.0-8.9) vulnerabilities. 30 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started