Microsoft
91,472 known vulnerabilities
Top Products
Microsoft Exchange Server Remote Code Execution Vulnerability
Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Windows HTML Platforms Security Feature Bypass Vulnerability
Microsoft Message Queuing Information Disclosure Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Reliability Analysis Metrics Calculation Engine (RACEng) Elevation of Privilege Vulnerability
Windows Projected File System Elevation of Privilege Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Office Visio Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Microsoft Exchange Remote Code Execution Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Microsoft Teams Remote Code Execution Vulnerability
Microsoft Teams Remote Code Execution Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated us
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by cre
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete
Fabasoft Cloud Enterprise Client 23.3.0.130 allows a user to escalate their privileges to local administrator.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine
An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an
When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only
Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who
Atera Agent through 1.8.3.6 on Windows Creates a Temporary File in a Directory with Insecure Permissions.
Privilege escalation vulnerability was discovered in Atera Agent 1.8.4.4 and prior on Windows due to mishandling of priv
An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update t
There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 11.0 and below on Windows and Linux
There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 11.1 and below that may allow a remote, authe
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge for Android Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Adobe InDesign versions 16.3 (and earlier), and 16.3.1 (and earlier) are affected by an out-of-bounds write vulnerabilit
There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow
IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF). This may allow an authent
IBM Sterling Connect:Express for UNIX 1.5 browser UI is vulnerable to attacks that rely on the use of cookies without th
IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Appliance 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.2 LTS
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.
IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.4 and 23.0.0 through 23.0.5 is vulnerable to disclosi
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insec
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function BackwardPass::IsEmpty
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::H
ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers:
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started