Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 139/380
5.5
CVE-2024-20762

Animate versions 24.0, 23.0.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclos

7.8
CVE-2024-20761

Animate versions 24.0, 23.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbi

5.5
CVE-2024-20757

Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclo

7.8
CVE-2024-20756

Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arb

7.8
CVE-2024-20755

Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result

7.8
CVE-2024-20752

Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary

7.8
CVE-2024-20746

Premiere Pro versions 24.1, 23.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in

7.8
CVE-2024-20745

Premiere Pro versions 24.1, 23.6.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could res

3.9
CVE-2024-26246

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

4.7
CVE-2024-26163

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

4.5
CVE-2024-27265

IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an atta

6.5
CVE-2024-1884

This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an atta

6.3
CVE-2024-1883

This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit

7.2
CVE-2024-1882

This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for

7.2
CVE-2024-1654

This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker

4.8
CVE-2024-1223

This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker

8.6
CVE-2024-1222

This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated

8.6
CVE-2020-11862

Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager on Linux

7.5
CVE-2024-26204

Outlook for Android Information Disclosure Vulnerability

7.3
CVE-2024-26203

Azure Data Studio Elevation of Privilege Vulnerability

6.6
CVE-2024-26201

Microsoft Intune Linux Agent Elevation of Privilege Vulnerability

7.8
CVE-2024-26199

Microsoft Office Elevation of Privilege Vulnerability

8.8
CVE-2024-26198

Microsoft Exchange Server Remote Code Execution Vulnerability

6.5
CVE-2024-26197

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

7.5
CVE-2024-26190

Microsoft QUIC Denial of Service Vulnerability

6.5
CVE-2024-26185

Windows Compressed Folder Tampering Vulnerability

7.8
CVE-2024-26182

Windows Kernel Elevation of Privilege Vulnerability

5.5
CVE-2024-26181

Windows Kernel Denial of Service Vulnerability

7.8
CVE-2024-26178

Windows Kernel Elevation of Privilege Vulnerability

5.5
CVE-2024-26177

Windows Kernel Information Disclosure Vulnerability

7.8
CVE-2024-26176

Windows Kernel Elevation of Privilege Vulnerability

5.5
CVE-2024-26174

Windows Kernel Information Disclosure Vulnerability

7.8
CVE-2024-26173

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2024-26170

Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability

7.8
CVE-2024-26169 KEV

Windows Error Reporting Service Elevation of Privilege Vulnerability

8.8
CVE-2024-26166

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

8.8
CVE-2024-26165

Visual Studio Code Elevation of Privilege Vulnerability

8.8
CVE-2024-26164

Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability

8.8
CVE-2024-26162

Microsoft ODBC Driver Remote Code Execution Vulnerability

8.8
CVE-2024-26161

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

5.5
CVE-2024-26160

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

8.8
CVE-2024-26159

Microsoft ODBC Driver Remote Code Execution Vulnerability

8.8
CVE-2024-21451

Microsoft ODBC Driver Remote Code Execution Vulnerability

8.8
CVE-2024-21450

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

5.0
CVE-2024-21448

Microsoft Teams for Android Information Disclosure Vulnerability

7.8
CVE-2024-21446

NTFS Elevation of Privilege Vulnerability

7.0
CVE-2024-21445

Windows USB Print Driver Elevation of Privilege Vulnerability

8.8
CVE-2024-21444

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

7.3
CVE-2024-21443

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2024-21442

Windows USB Print Driver Elevation of Privilege Vulnerability

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started