Microsoft
91,472 known vulnerabilities
Top Products
Azure Connected Machine Agent Elevation of Privilege Vulnerability
Windows DNS Spoofing Vulnerability
Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability
Microsoft Outlook for Mac Spoofing Vulnerability
Windows Media Remote Code Execution Vulnerability
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitra
microsoft-graph-core the Microsoft Graph Library for PHP. The Microsoft Graph Beta PHP SDK published packages which cont
msgraph-sdk-php is the Microsoft Graph Library for PHP. The Microsoft Graph PHP SDK published packages which contained t
Azure RTOS ThreadX is an advanced real-time operating system (RTOS) designed specifically for deeply embedded applicati
Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications.
Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications.
Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications.
Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications.
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authe
EzViz Studio v2.2.0 is vulnerable to DLL hijacking.
IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, and 11.5 is vulnerable to a denial of service th
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of ser
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embe
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed te
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embe
IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper inp
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a
IBM InfoSphere Information Server 11.7 could allow a remote attacker to cause a denial of service due to improper inp
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to exec
An issue was discovered in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, allows attackers
DLL Hijacking vulnerability in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, due to the i
An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, a
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the rend
Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 t
Certain WithSecure products allow a Denial of Service because there is an unpack handler crash that can lead to a scanni
Certain WithSecure products allow a Denial of Service because scanning a crafted file takes a long time, and causes the
An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve se
Stored XSS vulnerability. This vulnerability could allow an attacker to store a malicious JavaScript payload via GET and
Path traversal vulnerability whose exploitation could allow an authenticated remote user to bypass SecurityManager's int
A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller a
PowerShell Information Disclosure Vulnerability
IBM InfoSphere Information Server 11.7 could allow an authenticated user to change installation files due to incorrect f
Adobe FrameMaker Publishing Server versions 2022 and earlier are affected by an Improper Authentication vulnerability th
Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in a
Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Restriction of XML External Entity Reference
Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir
Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Input Validation vulnerability that could le
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started