Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 112/380
7.8
CVE-2024-49537

After Effects versions 24.6.2, 25.0.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could

7.8
CVE-2024-49513

PDFL SDK versions 21.0.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitra

7.8
CVE-2024-45156

Animate versions 23.0.8, 24.0.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could result i

7.8
CVE-2024-45155

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could

5.5
CVE-2024-49554

Media Encoder versions 25.0, 24.6.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could resu

7.8
CVE-2024-49553

Media Encoder versions 25.0, 24.6.3 and earlier are affected by an out-of-bounds write vulnerability that could result i

7.8
CVE-2024-49551

Media Encoder versions 25.0, 24.6.3 and earlier are affected by an out-of-bounds write vulnerability that could result i

6.3
CVE-2024-49535

Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by

5.5
CVE-2024-49531

Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by

5.4
CVE-2024-45761

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability.

6.1
CVE-2024-54138

NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to it

4.3
CVE-2024-49041

Microsoft Edge (Chromium-based) Spoofing Vulnerability

2.8
CVE-2024-53921

An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders

6.4
CVE-2024-21703

This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center a

7.6
CVE-2024-49053

Microsoft Dynamics 365 Sales Spoofing Vulnerability

8.2
CVE-2024-49052

Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate p

9.3
CVE-2024-49038

Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorize

8.7
CVE-2024-49035 KEV

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privil

5.5
CVE-2024-52998

Substance3D - Stager versions 3.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to d

4.3
CVE-2024-49054

Microsoft Edge (Chromium-based) Spoofing Vulnerability

6.5
CVE-2024-52056

Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any

4.9
CVE-2024-52055

Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any f

2.7
CVE-2024-52054

Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an

9.6
CVE-2024-52053

Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated att

7.2
CVE-2024-52052

Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom ap

5.5
CVE-2024-49529

InDesign Desktop versions 19.0, 20.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to

8.8
CVE-2024-11395

Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corru

9.8
CVE-2024-50919

Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file format

8.8
CVE-2024-49060

Azure Stack HCI Elevation of Privilege Vulnerability

5.5
CVE-2024-49536

Audition versions 23.6.9, 24.4.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disc

7.8
CVE-2024-46465

By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical file

8.2
CVE-2024-39726

IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity In

9.8
CVE-2022-1884

A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vu

5.4
CVE-2024-49025

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

6.7
CVE-2024-38668

Uncontrolled search path for some Intel(R) Quartus(R) Prime Standard Edition software for Windows before version 23.1.1

6.7
CVE-2024-38383

Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition software for Windows before version 24.2 may all

6.7
CVE-2024-36253

Uncontrolled search path in the Intel(R) SDP Tool for Windows software all version may allow an authenticated user to po

6.7
CVE-2024-35201

Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user

6.7
CVE-2024-28952

Uncontrolled search path for some Intel(R) IPP software for Windows before version 2021.12.0 may allow an authenticated

5.5
CVE-2024-49512

InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could le

5.5
CVE-2024-49511

InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could le

5.5
CVE-2024-49510

InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could le

7.8
CVE-2024-49509

InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that c

7.8
CVE-2024-49508

InDesign Desktop versions ID18.5.2, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that c

7.8
CVE-2024-49507

InDesign Desktop versions ID18.5.2, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that c

8.3
CVE-2024-11114

Inappropriate implementation in Views in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker who h

8.8
CVE-2024-11112

Use after free in Media in Google Chrome on Windows prior to 131.0.6778.69 allowed a remote attacker to potentially expl

7.2
CVE-2024-49042

Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability

5.5
CVE-2024-47458

Bridge versions 13.0.9, 14.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in

5.5
CVE-2024-47457

Illustrator versions 28.7.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started