Microsoft
91,472 known vulnerabilities
Top Products
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
Integer overflow or wraparound in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph
Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.
Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locall
Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose inform
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa
Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder w
Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacke
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker
IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE)
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based)
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized
OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe whi
IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an auth
IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated p
An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As
An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot
Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec
IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation
IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allow
IBM Cognos Controller 11.0.0 through 11.1.0 is vulnerable to a Client-Side Desync (CSD) attack where an attacker could e
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized a
Improper authorization in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 wit
IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handl
Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
NVIDIA Nemo Framework contains a vulnerability where a user could cause a relative path traversal issue by arbitrary fil
InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that cou
InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could r
InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that c
InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that cou
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started