Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 152/380
7.8
CVE-2023-44219

A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earli

7.1
CVE-2023-34058

VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operat

6.5
CVE-2023-5727

The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which c

7.0
CVE-2023-38041

A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a p

7.8
CVE-2023-45883

A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a sta

8.1
CVE-2023-4601

A stack-based buffer overflow vulnerability exists in NI System Configuration that could result in information disclosur

9.8
CVE-2023-38545

This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the h

3.7
CVE-2022-43892

IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could d

2.7
CVE-2022-43891

IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a det

2.7
CVE-2022-43893

IBM Security Verify Privilege On-Premises 11.5 could allow a privileged user to cause by using a malicious payload. IB

5.3
CVE-2022-43889

IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could

5.3
CVE-2022-22386

IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by

5.9
CVE-2022-22385

IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information to an attacked due to the transmiss

5.0
CVE-2022-22380

IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to spoof a trusted entity due to improperly vali

7.2
CVE-2022-22375

IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary command

4.3
CVE-2021-38859

IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a speciall

6.5
CVE-2021-29913

IBM Security Verify Privilege On-Premise 11.5 could allow an authenticated user to obtain sensitive information or perf

5.3
CVE-2021-20581

IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient s

4.3
CVE-2022-22384

IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to modify messages returned from the server due

5.3
CVE-2022-22377

IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by

5.3
CVE-2023-40373

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service with a specially cr

5.3
CVE-2023-40372

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a special

5.1
CVE-2023-38719

IBM Db2 11.5 could allow a local user with special privileges to cause a denial of service during database deactivation

5.3
CVE-2023-40374

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a special

7.5
CVE-2023-30991

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to denial of service with

5.3
CVE-2023-38740

IBM Db2 for Linux, UNIX, and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a spec

5.3
CVE-2023-38728

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic

5.3
CVE-2023-38720

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 and 11.5 is vulnerable to denial of service with

5.3
CVE-2023-30987

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of servic

4.2
CVE-2023-36559

Microsoft Edge (Chromium-based) Spoofing Vulnerability

5.5
CVE-2023-38217

Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by an Out-of-bounds Read vulnerability

5.5
CVE-2023-38216

Adobe Bridge versions 12.0.4 (and earlier) and 13.0.3 (and earlier) are affected by a Use After Free vulnerability that

7.8
CVE-2023-26370

Adobe Photoshop versions 23.5.5 (and earlier) and 24.7 (and earlier) are affected by an Access of Uninitialized Pointer

8.1
CVE-2023-41774

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41773

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

7.8
CVE-2023-41772

Win32k Elevation of Privilege Vulnerability

8.1
CVE-2023-41771

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41770

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41769

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41768

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41767

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

7.8
CVE-2023-41766

Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

8.1
CVE-2023-41765

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

5.3
CVE-2023-41763 KEV

Skype for Business Elevation of Privilege Vulnerability

7.5
CVE-2023-38171

Microsoft QUIC Denial of Service Vulnerability

8.1
CVE-2023-38166

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

7.0
CVE-2023-38159

Windows Graphics Component Elevation of Privilege Vulnerability

7.0
CVE-2023-36902

Windows Runtime Remote Code Execution Vulnerability

7.8
CVE-2023-36790

Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability

7.2
CVE-2023-36789

Skype for Business Remote Code Execution Vulnerability

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started