Microsoft
15,270 known vulnerabilities
Top Products
Improper input validation in Network in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker lev
Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had com
Improper input validation in ReadingList in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker
Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to execute
Incorrect authorization in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had
Type confusion in Accessibility in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had
Improper input validation in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who h
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentia
Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an
Improper input validation in NTP Footer in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker
Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote a
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentia
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentia
Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potential
Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social
Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potential
Out of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had
Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to poten
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a networ
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an aut
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an aut
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges ov
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privil
Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.
Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locall
In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abu
Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicl
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an au
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a net
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnera
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecu
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to el
Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution
Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulne
Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 15,270 CVE records in our database, including 470 critical and 10790 high severity vulnerabilities. 30 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 470 critical severity (CVSS 9.0+) and 10790 high severity (CVSS 7.0-8.9) vulnerabilities. 30 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started