Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 115/380
8.1
CVE-2024-43447

Windows SMBv3 Server Remote Code Execution Vulnerability

5.9
CVE-2024-38264

Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability

8.8
CVE-2024-38255

SQL Server Native Client Remote Code Execution Vulnerability

6.2
CVE-2024-38203

Windows Package Library Manager Information Disclosure Vulnerability

7.3
CVE-2024-9842

Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to crea

7.1
CVE-2024-8539

Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to mod

7.8
CVE-2024-7571

Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate the

7.8
CVE-2024-49528

Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in ar

5.5
CVE-2024-49527

Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to discl

7.8
CVE-2024-49526

Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrar

7.8
CVE-2024-49514

Photoshop Desktop versions 24.7.3, 25.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerabi

5.5
CVE-2024-47535

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan

7.5
CVE-2024-10668

There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root

0.0
CVE-2024-51736

Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when a

7.8
CVE-2024-9827

A maliciously crafted CATPART file when parsed in CC5Dll.dll through Autodesk AutoCAD can force an Out-of-Bounds Read vu

7.8
CVE-2024-9826

A maliciously crafted 3DM file when parsed in atf_api.dll through Autodesk AutoCAD can force a Use-After-Free vulnerabil

7.8
CVE-2024-8600

A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Memory Corruption vu

7.8
CVE-2024-8599

A maliciously crafted STP file when parsed in ACTranslators.exe through Autodesk AutoCAD can force a Memory Corruption v

7.8
CVE-2024-8598

A maliciously crafted STP file when parsed in ACTranslators.exe through Autodesk AutoCAD can force a Memory Corruption v

7.8
CVE-2024-8597

A maliciously crafted STP file when parsed in ASMDATAX230A.dll through Autodesk AutoCAD can force a Memory Corruption vu

7.8
CVE-2024-8596

A maliciously crafted MODEL file, when parsed in libodxdll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Writ

7.8
CVE-2024-8595

A maliciously crafted MODEL file when parsed in libodxdll.dll through Autodesk AutoCAD can force a Use-After-Free vulner

7.8
CVE-2024-8594

A maliciously crafted MODEL file when parsed in libodxdll.dll through Autodesk AutoCAD can force a Heap-Based Overflow v

7.8
CVE-2024-8593

A maliciously crafted CATPART file, when parsed in ASMKERN230A.dll through Autodesk AutoCAD, may force an Out-of-Bounds

7.8
CVE-2024-8592

A maliciously crafted CATPART file when parsed in AcTranslators.exe through Autodesk AutoCAD can force a Memory Corrupti

7.8
CVE-2024-8591

A maliciously crafted 3DM file when parsed in AcTranslators.exe through Autodesk AutoCAD can force a Heap-Based Buffer O

7.8
CVE-2024-8590

A maliciously crafted 3DM file when parsed in atf_api.dll through Autodesk AutoCAD can force a Use-After-Free vulnerabil

7.8
CVE-2024-8589

A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Out-of-Bounds Read v

7.8
CVE-2024-8588

A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Out-of-Bounds Read v

5.3
CVE-2024-49766

Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does no

6.1
CVE-2024-9949

Denial of Service in Forescout SecureConnector 11.1.02.1019 on Windows allows Unprivileged user to corrupt the configura

5.3
CVE-2024-31880

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv

7.8
CVE-2024-48903

An improper access control vulnerability in Trend Micro Deep Security Agent 20 could allow a local attacker to escalate

4.3
CVE-2024-43577

Microsoft Edge (Chromium-based) Spoofing Vulnerability

5.9
CVE-2024-49023

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

6.5
CVE-2024-43596

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

6.5
CVE-2024-43595

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

5.9
CVE-2024-43587

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

5.4
CVE-2024-43580

Microsoft Edge (Chromium-based) Spoofing Vulnerability

7.6
CVE-2024-43579

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

7.6
CVE-2024-43578

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

7.5
CVE-2024-43566

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

5.5
CVE-2024-45072

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when process

5.5
CVE-2024-45071

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a p

7.5
CVE-2024-38204

Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network.

8.6
CVE-2024-38190

Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a netwo

8.7
CVE-2024-38139

Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

8.8
CVE-2024-9965

Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker wh

9.1
CVE-2024-49388

Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Pro

7.5
CVE-2024-49387

Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started