Microsoft
91,472 known vulnerabilities
Top Products
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr
Altair is a GraphQL Client. Prior to version 5.2.5, the Altair GraphQL Client Desktop Application does not sanitize exte
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acr
Incorrect Default Permissions vulnerability in Hitachi JP1/Performance Management on Windows allows File Manipulation.Th
A vulnerability was found in WhiteHSBG JNDIExploit 1.4 on Windows. It has been rated as problematic. Affected by this is
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remo
An issue in Binalyze IREC.sys v.3.11.0 and before allows a local attacker to execute arbitrary code and escalate privile
If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer
A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that
Stored cross-site scripting (XSS) vulnerability in protection plan name. The following products are affected: Acronis Cy
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Ac
Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Prote
Sensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber
Sensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber
Sensitive information disclosure due to cleartext storage of sensitive information. The following products are affected:
Sensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis C
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec
Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Li
Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Wind
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Ac
Sensitive information disclosure due to cleartext storage of sensitive information in memory. The following products are
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: A
yt-dlp is a youtube-dl fork with additional features and fixes. yt-dlp allows the user to provide shell command lines to
Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Clien
Certain WithSecure products allow Local privilege escalation via the lhz archive unpack handler. This affects WithSecure
Certain WithSecure products allow Denial of Service in the aeelf component. This affects WithSecure Client Security 15,
Certain WithSecure products allow Denial of Service (infinite loop). This affects WithSecure Client Security 15, WithSec
Certain WithSecure products allow Denial of Service via a fuzzed PE32 file. This affects WithSecure Client Security 15,
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber
An issue was discovered in ImfHpRegFilter.sys in IOBit Malware Fighter version 8.0.2, allows local attackers to cause a
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free
An issue was discovered in Qt before 5.15.16, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3 on Windows. When u
Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSec
Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSec
Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file. This affects WithSecur
Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file. T
Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file. This affects
Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files. This affe
Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files. This affects
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl
A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerabi
Razer Synapse through 3.7.1209.121307 allows privilege escalation due to an unsafe installation path and improper privil
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user
Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affect
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started