Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 141/380
5.4
CVE-2023-48679

Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products

5.5
CVE-2023-48678

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber

7.3
CVE-2024-0819

Improper initialization of default settings in TeamViewer Remote Client prior version 15.51.5 for Windows, Linux and ma

7.8
CVE-2024-0197

A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate the

7.8
CVE-2023-7016

A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYST

7.8
CVE-2023-5993

A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker

8.2
CVE-2024-26192

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

4.3
CVE-2024-26188

Microsoft Edge (Chromium-based) Spoofing Vulnerability

4.8
CVE-2024-21423

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

8.6
CVE-2022-43842

IBM Aspera Console 3.4.0 through 3.4.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ

7.6
CVE-2024-0715

Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue a

5.5
CVE-2024-20749

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that

5.5
CVE-2024-20748

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that

5.5
CVE-2024-20747

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that

7.8
CVE-2024-20739

Audition versions 24.0.3, 23.6.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could resul

9.8
CVE-2024-20738

Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability

5.5
CVE-2024-20736

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that

5.5
CVE-2024-20735

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that

5.5
CVE-2024-20734

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could

5.5
CVE-2024-20733

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an Improper Input Validation vulnerabilit

7.8
CVE-2024-20731

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could

7.8
CVE-2024-20730

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an Integer Overflow or Wraparound vulnera

7.8
CVE-2024-20729

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could

7.8
CVE-2024-20728

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds write vulnerability that

7.8
CVE-2024-20727

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds write vulnerability that

7.8
CVE-2024-20726

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds write vulnerability that

7.5
CVE-2023-50387

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to c

8.8
CVE-2024-21420

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

9.8
CVE-2024-21413 KEV

Microsoft Outlook Remote Code Execution Vulnerability

8.1
CVE-2024-21412 KEV

Internet Shortcut Files Security Feature Bypass Vulnerability

9.8
CVE-2024-21410 KEV

Microsoft Exchange Server Elevation of Privilege Vulnerability

7.5
CVE-2024-21406

Windows Printing Service Spoofing Vulnerability

7.0
CVE-2024-21405

Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability

7.5
CVE-2024-21404

.NET Denial of Service Vulnerability

9.0
CVE-2024-21403

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

7.1
CVE-2024-21402

Microsoft Outlook Elevation of Privilege Vulnerability

9.8
CVE-2024-21401

Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability

5.3
CVE-2024-21397

Microsoft Azure File Sync Elevation of Privilege Vulnerability

7.6
CVE-2024-21396

Dynamics 365 Sales Spoofing Vulnerability

8.2
CVE-2024-21395

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

7.6
CVE-2024-21394

Dynamics 365 Field Service Spoofing Vulnerability

7.6
CVE-2024-21393

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

8.8
CVE-2024-21391

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

7.6
CVE-2024-21389

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

7.5
CVE-2024-21386

.NET Denial of Service Vulnerability

7.8
CVE-2024-21384

Microsoft Office OneNote Remote Code Execution Vulnerability

6.8
CVE-2024-21381

Microsoft Azure Active Directory B2C Spoofing Vulnerability

8.0
CVE-2024-21380

Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability

7.8
CVE-2024-21379

Microsoft Word Remote Code Execution Vulnerability

8.8
CVE-2024-21378

Microsoft Outlook Remote Code Execution Vulnerability

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started