Microsoft
91,472 known vulnerabilities
Top Products
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret
IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticat
An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection t
Dell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted Search Path
Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a ne
Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowf
A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows enviro
IBM Storage Protect for Virtual Environments: Data Protection for VMware and Storage Protect Backup-Archive Client 8.1.0
IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated
IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have acc
IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.
User Interface (UI) Misrepresentation of Critical Information in Microsoft Edge (Chromium-based) allows an unauthorized
IBM InfoSphere Information Server 11.7 could allow a remote user to obtain sensitive version information that could aid
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.11 is vulnerable to stored cross-site scriptin
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inje
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker
IBM App Connect Enterprise 12.0.1.0 through 12.0.7.0and 13.0.1.0 under certain configurations could allow a privileged u
Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Proc
Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS
Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowed a remote attacker
Animate versions 24.0.6, 23.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that
Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result i
Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result i
Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result i
Substance3D - Stager versions 3.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could re
Substance3D - Stager versions 3.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could r
Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Uncontrolled Search Path Element vulnerability tha
Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerabili
Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
Visual Studio Elevation of Privilege Vulnerability
On-Premises Data Gateway Information Disclosure Vulnerability
Microsoft Office OneNote Remote Code Execution Vulnerability
Microsoft Access Remote Code Execution Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker
Windows Graphics Component Elevation of Privilege Vulnerability
Windows CSC Service Elevation of Privilege Vulnerability
Windows CSC Service Information Disclosure Vulnerability
Microsoft Brokering File System Elevation of Privilege Vulnerability
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
Microsoft Access Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started