Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 129/380
7.5
CVE-2024-30101

Microsoft Office Remote Code Execution Vulnerability

7.8
CVE-2024-30100

Microsoft SharePoint Server Remote Code Execution Vulnerability

7.0
CVE-2024-30099

Windows Kernel Elevation of Privilege Vulnerability

8.8
CVE-2024-30097

Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability

5.5
CVE-2024-30096

Windows Cryptographic Services Information Disclosure Vulnerability

7.8
CVE-2024-30095

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

7.8
CVE-2024-30094

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

7.3
CVE-2024-30093

Windows Storage Elevation of Privilege Vulnerability

7.8
CVE-2024-30091

Win32k Elevation of Privilege Vulnerability

7.0
CVE-2024-30090

Microsoft Streaming Service Elevation of Privilege Vulnerability

7.8
CVE-2024-30089

Microsoft Streaming Service Elevation of Privilege Vulnerability

7.0
CVE-2024-30088 KEV

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2024-30087

Win32k Elevation of Privilege Vulnerability

7.8
CVE-2024-30086

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

7.8
CVE-2024-30085

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

7.0
CVE-2024-30084

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

7.5
CVE-2024-30083

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

7.8
CVE-2024-30082

Win32k Elevation of Privilege Vulnerability

9.8
CVE-2024-30080

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

8.8
CVE-2024-30078

Windows Wi-Fi Driver Remote Code Execution Vulnerability

8.0
CVE-2024-30077

Windows OLE Remote Code Execution Vulnerability

6.8
CVE-2024-30076

Windows Container Manager Service Elevation of Privilege Vulnerability

8.0
CVE-2024-30075

Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability

8.0
CVE-2024-30074

Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability

7.8
CVE-2024-30072

Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability

7.5
CVE-2024-30070

DHCP Server Service Denial of Service Vulnerability

4.7
CVE-2024-30069

Windows Remote Access Connection Manager Information Disclosure Vulnerability

8.8
CVE-2024-30068

Windows Kernel Elevation of Privilege Vulnerability

5.5
CVE-2024-30067

Winlogon Elevation of Privilege Vulnerability

5.5
CVE-2024-30066

Winlogon Elevation of Privilege Vulnerability

5.5
CVE-2024-30065

Windows Themes Denial of Service Vulnerability

8.8
CVE-2024-30064

Windows Kernel Elevation of Privilege Vulnerability

6.7
CVE-2024-30063

Windows Distributed File System (DFS) Remote Code Execution Vulnerability

7.8
CVE-2024-30062

Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability

4.7
CVE-2024-30052

Visual Studio Remote Code Execution Vulnerability

6.7
CVE-2024-29060

Visual Studio Elevation of Privilege Vulnerability

6.5
CVE-2024-5692

On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file w

7.8
CVE-2024-36358

A link following vulnerability in Trend Micro Deep Security 20.x agents below build 20.0.1-3180 could allow a local atta

7.8
CVE-2024-32849

Trend Micro Security 17.x (Consumer) is vulnerable to a Privilege Escalation vulnerability that could allow a local atta

7.0
CVE-2024-5102

A sym-linked file accessed via the repair function in Avast Antivirus <24.2 on Windows may allow user to elevate privile

9.8
CVE-2024-4577 KEV

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows,

6.5
CVE-2023-45188

IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files

7.8
CVE-2024-1694

Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to bypass d

9.8
CVE-2024-37385

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_ide

9.1
CVE-2024-2362

A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. Due to improper

7.5
CVE-2024-35178

The Jupyter Server provides the backend for Jupyter web applications. Jupyter Server on Windows has a vulnerability that

7.8
CVE-2023-38042

A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to ex

8.8
CVE-2024-5495

Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap co

8.8
CVE-2024-5494

Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap co

8.2
CVE-2024-29072

A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started