Microsoft
91,472 known vulnerabilities
Top Products
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service o
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows a
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an aut
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unau
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges loca
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a n
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a netwo
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elev
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevat
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges ove
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privile
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows a
Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially per
Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromise
Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a us
Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-le
An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated ac
An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated a
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofin
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a n
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized atta
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege esca
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started