Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 134/380
8.8
CVE-2024-4018

Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api mo

8.8
CVE-2024-4017

Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (filesystem modules) al

5.0
CVE-2024-29991

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

6.5
CVE-2024-29987

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

5.4
CVE-2024-29986

Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability

7.3
CVE-2024-24910

A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for

4.3
CVE-2023-4509

It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.

6.1
CVE-2024-3841

Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to in

7.8
CVE-2024-21111

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a

6.7
CVE-2024-21107

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a

8.8
CVE-2024-22014

An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated p

7.8
CVE-2024-32488

In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak p

7.8
CVE-2024-30273

Illustrator versions 28.3, 27.9.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could res

7.8
CVE-2024-30272

Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds write vulnerability that could result in

7.8
CVE-2024-30271

Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds write vulnerability that could result in

7.8
CVE-2024-20797

Animate versions 23.0.4, 24.0.1 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted f

5.5
CVE-2024-20796

Animate versions 23.0.4, 24.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to discl

7.8
CVE-2024-20795

Animate versions 23.0.4, 24.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could r

5.5
CVE-2024-20794

Animate versions 23.0.4, 24.0.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to

5.5
CVE-2024-20798

Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to dis

5.5
CVE-2024-20771

Bridge versions 13.0.6, 14.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclo

8.8
CVE-2024-26362

HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to r

9.8
CVE-2024-3566

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d

7.8
CVE-2024-20772

Media Encoder versions 24.2.1, 23.6.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could

5.5
CVE-2024-20770

Photoshop Desktop versions 24.7.2, 25.3.1 and earlier are affected by an out-of-bounds read vulnerability that could lea

5.5
CVE-2024-20766

InDesign Desktop versions 18.5.1, 19.2 and earlier are affected by an out-of-bounds read vulnerability that could lead t

5.5
CVE-2024-20737

After Effects versions 24.1, 23.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to d

10.0
CVE-2024-24576

Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to versi

8.8
CVE-2024-29993

Azure CycleCloud Elevation of Privilege Vulnerability

5.5
CVE-2024-29992

Azure Identity Library for .NET Information Disclosure Vulnerability

9.0
CVE-2024-29990

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

8.4
CVE-2024-29989

Azure Monitor Agent Elevation of Privilege Vulnerability

8.8
CVE-2024-29988 KEV

SmartScreen Prompt Security Feature Bypass Vulnerability

8.8
CVE-2024-29985

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

8.8
CVE-2024-29984

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

8.8
CVE-2024-29983

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

8.8
CVE-2024-29982

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

7.2
CVE-2024-29066

Windows Distributed File System (DFS) Remote Code Execution Vulnerability

6.2
CVE-2024-29064

Windows Hyper-V Denial of Service Vulnerability

7.3
CVE-2024-29063

Azure AI Search Information Disclosure Vulnerability

7.1
CVE-2024-29062

Secure Boot Security Feature Bypass Vulnerability

7.8
CVE-2024-29061

Secure Boot Security Feature Bypass Vulnerability

4.3
CVE-2024-29056

Windows Authentication Elevation of Privilege Vulnerability

7.2
CVE-2024-29055

Microsoft Defender for IoT Elevation of Privilege Vulnerability

7.2
CVE-2024-29054

Microsoft Defender for IoT Elevation of Privilege Vulnerability

8.8
CVE-2024-29053

Microsoft Defender for IoT Remote Code Execution Vulnerability

7.8
CVE-2024-29052

Windows Storage Elevation of Privilege Vulnerability

8.4
CVE-2024-29050

Windows Cryptographic Services Remote Code Execution Vulnerability

8.8
CVE-2024-29048

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

8.8
CVE-2024-29047

Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started