Microsoft
91,472 known vulnerabilities
Top Products
A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earli
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operat
The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which c
A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a p
A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a sta
A stack-based buffer overflow vulnerability exists in NI System Configuration that could result in information disclosur
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the h
IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could d
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a det
IBM Security Verify Privilege On-Premises 11.5 could allow a privileged user to cause by using a malicious payload. IB
IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by
IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information to an attacked due to the transmiss
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to spoof a trusted entity due to improperly vali
IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary command
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a speciall
IBM Security Verify Privilege On-Premise 11.5 could allow an authenticated user to obtain sensitive information or perf
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient s
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to modify messages returned from the server due
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service with a specially cr
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a special
IBM Db2 11.5 could allow a local user with special privileges to cause a denial of service during database deactivation
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a special
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to denial of service with
IBM Db2 for Linux, UNIX, and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a spec
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 and 11.5 is vulnerable to denial of service with
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by an Out-of-bounds Read vulnerability
Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by a Use After Free vulnerability that
Adobe Photoshop versions 23.5.5 (and earlier) and 24.7 (and earlier) are affected by an Access of Uninitialized Pointer
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Win32k Elevation of Privilege Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Skype for Business Elevation of Privilege Vulnerability
Microsoft QUIC Denial of Service Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
Windows Runtime Remote Code Execution Vulnerability
Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability
Skype for Business Remote Code Execution Vulnerability
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started