Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 105/380
3.3
CVE-2024-56467

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret

7.1
CVE-2024-54171

IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticat

3.1
CVE-2025-23415

An insufficient verification of data authenticity vulnerability exists in BIG-IP APM Access Policy endpoint inspection t

7.8
CVE-2025-21107

Dell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted Search Path

9.9
CVE-2025-21415

Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a ne

8.2
CVE-2025-21396

Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.

7.8
CVE-2025-24789

Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowf

5.5
CVE-2025-23084

A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows enviro

5.9
CVE-2024-38320

IBM Storage Protect for Virtual Environments: Data Protection for VMware and Storage Protect Backup-Archive Client 8.1.0

5.4
CVE-2024-37527

IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated

6.5
CVE-2023-50946

IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have acc

6.2
CVE-2023-50945

IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.

5.4
CVE-2025-21262

User Interface (UI) Misrepresentation of Critical Information in Microsoft Edge (Chromium-based) allows an unauthorized

5.3
CVE-2024-40706

IBM InfoSphere Information Server 11.7 could allow a remote user to obtain sensitive version information that could aid

6.4
CVE-2025-23227

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.11 is vulnerable to stored cross-site scriptin

9.1
CVE-2024-41783

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inje

9.1
CVE-2024-38337

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker

4.4
CVE-2024-49338

IBM App Connect Enterprise 12.0.1.0 through 12.0.7.0and 13.0.1.0 under certain configurations could allow a privileged u

7.4
CVE-2025-21399

Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability

6.5
CVE-2025-21185

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

6.5
CVE-2024-52363

IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker

7.8
CVE-2025-21325

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

4.3
CVE-2024-54540

The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Proc

9.1
CVE-2025-0502

Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS

6.5
CVE-2025-0440

Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowed a remote attacker

7.8
CVE-2025-21135

Animate versions 24.0.6, 23.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that

7.8
CVE-2025-21132

Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result i

7.8
CVE-2025-21131

Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result i

7.8
CVE-2025-21130

Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result i

7.8
CVE-2025-21129

Substance3D - Stager versions 3.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could re

7.8
CVE-2025-21128

Substance3D - Stager versions 3.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could r

7.8
CVE-2025-21127

Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Uncontrolled Search Path Element vulnerability tha

7.8
CVE-2025-21122

Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerabili

8.8
CVE-2025-21417

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21413

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21411

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21409

Windows Telephony Service Remote Code Execution Vulnerability

7.3
CVE-2025-21405

Visual Studio Elevation of Privilege Vulnerability

6.4
CVE-2025-21403

On-Premises Data Gateway Information Disclosure Vulnerability

7.8
CVE-2025-21402

Microsoft Office OneNote Remote Code Execution Vulnerability

7.8
CVE-2025-21395

Microsoft Access Remote Code Execution Vulnerability

6.3
CVE-2025-21393

Microsoft SharePoint Server Spoofing Vulnerability

7.5
CVE-2025-21389

Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker

7.8
CVE-2025-21382

Windows Graphics Component Elevation of Privilege Vulnerability

7.8
CVE-2025-21378

Windows CSC Service Elevation of Privilege Vulnerability

5.5
CVE-2025-21374

Windows CSC Service Information Disclosure Vulnerability

7.8
CVE-2025-21372

Microsoft Brokering File System Elevation of Privilege Vulnerability

7.8
CVE-2025-21370

Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

7.8
CVE-2025-21366

Microsoft Access Remote Code Execution Vulnerability

7.8
CVE-2025-21365

Microsoft Office Remote Code Execution Vulnerability

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started