Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 150/380
6.5
CVE-2023-22290

Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable denial of servic

7.5
CVE-2023-22285

Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of

2.2
CVE-2022-46647

Insertion of sensitive information into log file for some Intel Unison software may allow an authenticated user to poten

2.2
CVE-2022-46646

Exposure of sensitive information to an unauthorized actor for some Intel Unison software may allow an authenticated use

1.9
CVE-2022-46301

Improper Initialization for some Intel Unison software may allow a privileged user to potentially enable denial of servi

3.3
CVE-2022-46299

Insufficient control flow management for some Intel Unison software may allow an authenticated user to potentially enabl

1.9
CVE-2022-46298

Incomplete cleanup for some Intel Unison software may allow a privileged user to potentially enable denial of service vi

2.2
CVE-2022-45469

Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalatio

3.3
CVE-2022-45109

Improper initialization for some Intel Unison software may allow an authenticated user to potentially enable information

3.3
CVE-2022-43666

Exposure of sensitive system information due to uncleared debug information for some Intel Unison software may allow an

3.3
CVE-2022-43477

Incomplete cleanup for some Intel Unison software may allow an authenticated user to potentially enable information disc

8.2
CVE-2022-36396

Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmiEdit-Linux-5.27.06.0

7.5
CVE-2022-36374

Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.000

6.1
CVE-2023-38177

Microsoft SharePoint Server Remote Code Execution Vulnerability

8.8
CVE-2023-38151

Microsoft Host Integration Server 2020 Remote Code Execution Vulnerability

7.8
CVE-2023-36719

Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability

7.8
CVE-2023-36705

Windows Installer Elevation of Privilege Vulnerability

8.8
CVE-2023-36560

ASP.NET Security Feature Bypass Vulnerability

8.0
CVE-2023-36439

Microsoft Exchange Server Remote Code Execution Vulnerability

5.5
CVE-2023-36428

Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

7.0
CVE-2023-36427

Windows Hyper-V Elevation of Privilege Vulnerability

8.0
CVE-2023-36425

Windows Distributed File System (DFS) Remote Code Execution Vulnerability

7.8
CVE-2023-36424 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

8.8
CVE-2023-36423

Microsoft Remote Registry Service Remote Code Execution Vulnerability

7.8
CVE-2023-36422

Microsoft Windows Defender Elevation of Privilege Vulnerability

6.5
CVE-2023-36413

Microsoft Office Security Feature Bypass Vulnerability

7.6
CVE-2023-36410

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

7.8
CVE-2023-36408

Windows Hyper-V Elevation of Privilege Vulnerability

7.8
CVE-2023-36407

Windows Hyper-V Elevation of Privilege Vulnerability

5.5
CVE-2023-36406

Windows Hyper-V Information Disclosure Vulnerability

7.0
CVE-2023-36405

Windows Kernel Elevation of Privilege Vulnerability

5.5
CVE-2023-36404

Windows Kernel Information Disclosure Vulnerability

7.0
CVE-2023-36403

Windows Kernel Elevation of Privilege Vulnerability

8.8
CVE-2023-36402

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

7.2
CVE-2023-36401

Microsoft Remote Registry Service Remote Code Execution Vulnerability

8.8
CVE-2023-36400

Windows HMAC Key Derivation Elevation of Privilege Vulnerability

7.1
CVE-2023-36399

Windows Storage Elevation of Privilege Vulnerability

6.5
CVE-2023-36398

Windows NTFS Information Disclosure Vulnerability

9.8
CVE-2023-36397

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

7.8
CVE-2023-36396

Windows Compressed Folder Remote Code Execution Vulnerability

7.5
CVE-2023-36395

Windows Deployment Services Denial of Service Vulnerability

7.0
CVE-2023-36394

Windows Search Service Elevation of Privilege Vulnerability

7.8
CVE-2023-36393

Windows User Interface Application Core Remote Code Execution Vulnerability

7.5
CVE-2023-36392

DHCP Server Service Denial of Service Vulnerability

8.6
CVE-2023-36052

Azure CLI REST Command Information Disclosure Vulnerability

8.0
CVE-2023-36050

Microsoft Exchange Server Spoofing Vulnerability

7.8
CVE-2023-36047

Windows Authentication Elevation of Privilege Vulnerability

7.1
CVE-2023-36046

Windows Authentication Denial of Service Vulnerability

7.8
CVE-2023-36045

Microsoft Office Graphics Remote Code Execution Vulnerability

6.5
CVE-2023-36043

Open Management Infrastructure Information Disclosure Vulnerability

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started