Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 140/380
8.8
CVE-2024-21441

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

8.8
CVE-2024-21440

Microsoft ODBC Driver Remote Code Execution Vulnerability

7.0
CVE-2024-21439

Windows Telephony Server Elevation of Privilege Vulnerability

7.5
CVE-2024-21438

Microsoft AllJoyn API Denial of Service Vulnerability

7.8
CVE-2024-21437

Windows Graphics Component Elevation of Privilege Vulnerability

7.8
CVE-2024-21436

Windows Installer Elevation of Privilege Vulnerability

8.8
CVE-2024-21435

Windows OLE Remote Code Execution Vulnerability

7.8
CVE-2024-21434

Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability

7.0
CVE-2024-21433

Windows Print Spooler Elevation of Privilege Vulnerability

7.0
CVE-2024-21432

Windows Update Stack Elevation of Privilege Vulnerability

7.8
CVE-2024-21431

Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability

5.7
CVE-2024-21430

Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability

6.8
CVE-2024-21429

Windows USB Hub Driver Remote Code Execution Vulnerability

7.5
CVE-2024-21427

Windows Kerberos Security Feature Bypass Vulnerability

7.8
CVE-2024-21426

Microsoft SharePoint Server Remote Code Execution Vulnerability

7.5
CVE-2024-21421

Azure SDK Spoofing Vulnerability

7.6
CVE-2024-21419

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

5.5
CVE-2024-21408

Windows Hyper-V Denial of Service Vulnerability

8.1
CVE-2024-21407

Windows Hyper-V Remote Code Execution Vulnerability

9.0
CVE-2024-21400

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

7.5
CVE-2024-21392

.NET and Visual Studio Denial of Service Vulnerability

7.1
CVE-2024-21390

Microsoft Authenticator Elevation of Privilege Vulnerability

9.8
CVE-2024-21334

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

7.8
CVE-2024-21330

Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability

5.5
CVE-2024-20671

Microsoft Defender Security Feature Bypass Vulnerability

8.8
CVE-2024-0670

Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to e

4.3
CVE-2024-26167

Microsoft Edge for Android Spoofing Vulnerability

5.6
CVE-2024-1460

MSI Afterburner v4.6.5.16370 is vulnerable to a Kernel Memory Leak vulnerability by triggering the 0x80002040 IOCTL code

4.4
CVE-2024-1443

MSI Afterburner v4.6.5.16370 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002000 IOCTL code

7.3
CVE-2024-27303

electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Wind

8.2
CVE-2024-20337

A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacke

7.5
CVE-2024-24278

An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive informa

9.6
CVE-2024-24275

Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker t

7.8
CVE-2024-20765

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could

6.1
CVE-2024-0590

The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ

5.5
CVE-2023-44347

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a NULL Pointer Dereference vulne

5.5
CVE-2023-44346

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerabil

5.5
CVE-2023-44345

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a Improper Input Validation vuln

5.5
CVE-2023-44344

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerabil

5.5
CVE-2023-44343

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerabil

5.5
CVE-2023-44342

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by an out-of-bounds read vulnerabil

5.5
CVE-2023-44341

Adobe InDesign versions ID18.5 (and earlier) and ID17.4.2 (and earlier) are affected by a NULL Pointer Dereference vulne

5.5
CVE-2023-25926

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Inje

8.5
CVE-2023-25921

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer f

8.5
CVE-2023-25925

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker

4.3
CVE-2023-25922

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer fi

9.8
CVE-2024-27099

The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect `AMQP_VALUE` f

5.4
CVE-2023-48682

Stored cross-site scripting (XSS) vulnerability in unit name. The following products are affected: Acronis Cyber Protect

6.1
CVE-2023-48681

Self cross-site scripting (XSS) vulnerability in storage nodes search field. The following products are affected: Acroni

5.5
CVE-2023-48680

Sensitive information disclosure due to excessive collection of system information. The following products are affected:

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started