Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 128/380
8.8
CVE-2024-21414

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

8.8
CVE-2024-21398

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

8.8
CVE-2024-21373

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

8.8
CVE-2024-21335

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

8.8
CVE-2024-21333

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

8.8
CVE-2024-21332

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

8.8
CVE-2024-21331

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

8.8
CVE-2024-21317

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

8.8
CVE-2024-21308

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

8.8
CVE-2024-21303

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

8.8
CVE-2024-20701

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

7.8
CVE-2024-4944

A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user t

7.8
CVE-2024-34122

Acrobat for Edge versions 126.0.2592.68 and earlier are affected by an out-of-bounds read vulnerability when parsing a c

7.5
CVE-2024-36991

In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on t

7.5
CVE-2024-24749

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.2

8.0
CVE-2024-35260

An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over

8.8
CVE-2024-6293

Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap co

8.8
CVE-2024-6292

Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap co

5.3
CVE-2024-33881

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileD

5.3
CVE-2024-33880

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathname

9.8
CVE-2024-33879

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileD

6.3
CVE-2024-36071

Samsung Magician 8.0.0 on Windows allows an admin to escalate privileges by tampering with the directory and DLL files u

4.3
CVE-2024-38093

Microsoft Edge (Chromium-based) Spoofing Vulnerability

4.7
CVE-2024-38082

Microsoft Edge (Chromium-based) Spoofing Vulnerability

5.4
CVE-2024-0103

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user may cause an incorrect Initialization of

9.0
CVE-2024-0095

NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and ex

5.5
CVE-2024-0092

NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of excepti

7.8
CVE-2024-0091

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer der

7.8
CVE-2024-0090

NVIDIA GPU driver for Windows and Linux contains a vulnerability where a user can cause an out-of-bounds write. A succes

7.8
CVE-2024-0089

NVIDIA GPU Display Driver for Windows contains a vulnerability where the information from a previous client or another p

6.3
CVE-2024-0085

NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged op

4.3
CVE-2024-38083

Microsoft Edge (Chromium-based) Spoofing Vulnerability

5.4
CVE-2024-30058

Microsoft Edge (Chromium-based) Spoofing Vulnerability

5.4
CVE-2024-30057

Microsoft Edge for iOS Spoofing Vulnerability

7.5
CVE-2024-30472

Telemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthen

7.8
CVE-2024-20753

Photoshop Desktop versions 24.7.3, 25.7 and earlier are affected by an out-of-bounds read vulnerability when parsing a c

6.1
CVE-2024-37304

NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to it

8.1
CVE-2024-37325

Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability

7.0
CVE-2024-35265

Windows Perception Service Elevation of Privilege Vulnerability

5.7
CVE-2024-35263

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

5.5
CVE-2024-35255

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

7.1
CVE-2024-35254

Azure Monitor Agent Elevation of Privilege Vulnerability

4.4
CVE-2024-35253

Microsoft Azure File Sync Elevation of Privilege Vulnerability

7.5
CVE-2024-35252

Azure Storage Movement Client Library Denial of Service Vulnerability

7.8
CVE-2024-35250 KEV

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

8.8
CVE-2024-35249

Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability

7.3
CVE-2024-35248

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

7.8
CVE-2024-30104

Microsoft Office Remote Code Execution Vulnerability

8.8
CVE-2024-30103

Microsoft Outlook Remote Code Execution Vulnerability

7.3
CVE-2024-30102

Microsoft Office Remote Code Execution Vulnerability

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started