Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 161/380
8.0
CVE-2023-35388

Microsoft Exchange Server Remote Code Execution Vulnerability

8.8
CVE-2023-35387

Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability

7.8
CVE-2023-35386

Windows Kernel Elevation of Privilege Vulnerability

9.8
CVE-2023-35385

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

5.4
CVE-2023-35384

Windows HTML Platforms Security Feature Bypass Vulnerability

7.5
CVE-2023-35383

Microsoft Message Queuing Information Disclosure Vulnerability

7.8
CVE-2023-35382

Windows Kernel Elevation of Privilege Vulnerability

8.8
CVE-2023-35381

Windows Fax Service Remote Code Execution Vulnerability

7.8
CVE-2023-35380

Windows Kernel Elevation of Privilege Vulnerability

7.8
CVE-2023-35379

Reliability Analysis Metrics Calculation Engine (RACEng) Elevation of Privilege Vulnerability

7.0
CVE-2023-35378

Windows Projected File System Elevation of Privilege Vulnerability

6.5
CVE-2023-35377

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

6.5
CVE-2023-35376

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

7.8
CVE-2023-35372

Microsoft Office Visio Remote Code Execution Vulnerability

7.8
CVE-2023-35371

Microsoft Office Remote Code Execution Vulnerability

8.8
CVE-2023-35368

Microsoft Exchange Remote Code Execution Vulnerability

7.8
CVE-2023-35359

Windows Kernel Elevation of Privilege Vulnerability

8.8
CVE-2023-29330

Microsoft Teams Remote Code Execution Vulnerability

8.8
CVE-2023-29328

Microsoft Teams Remote Code Execution Vulnerability

9.8
CVE-2023-21709

Microsoft Exchange Server Elevation of Privilege Vulnerability

7.8
CVE-2023-20562

Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user

5.5
CVE-2023-20561

Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated

5.5
CVE-2023-20556

Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated us

6.5
CVE-2023-38157

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

7.5
CVE-2023-32783

The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by cre

9.8
CVE-2023-39143

PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete

7.8
CVE-2023-32764

Fabasoft Cloud Enterprise Client 23.3.0.130 allows a user to escalate their privileges to local administrator.

7.4
CVE-2023-4136

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine

7.1
CVE-2023-36858

An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an

5.5
CVE-2023-4054

When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only

8.8
CVE-2023-2313

Inappropriate implementation in Sandbox in Google Chrome on Windows prior to 112.0.5615.49 allowed a remote attacker who

7.8
CVE-2023-26077

Atera Agent through 1.8.3.6 on Windows Creates a Temporary File in a Directory with Insecure Permissions.

7.8
CVE-2023-26078

Privilege escalation vulnerability was discovered in Atera Agent 1.8.4.4 and prior on Windows due to mishandling of priv

7.5
CVE-2023-35077

An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update t

6.1
CVE-2023-25841

There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 11.0 and below on Windows and Linux

3.4
CVE-2023-25840

There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 11.1 and below that may allow a remote, authe

6.5
CVE-2023-38187

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

4.3
CVE-2023-38173

Microsoft Edge for Android Spoofing Vulnerability

4.7
CVE-2023-35392

Microsoft Edge (Chromium-based) Spoofing Vulnerability

7.8
CVE-2021-39822

Adobe InDesign versions 16.3 (and earlier), and 16.3.1 (and earlier) are affected by an out-of-bounds write vulnerabilit

7.0
CVE-2023-25839

There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow

6.5
CVE-2023-29260

IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF). This may allow an authent

3.7
CVE-2023-29259

IBM Sterling Connect:Express for UNIX 1.5 browser UI is vulnerable to attacks that rely on the use of cookies without th

5.9
CVE-2023-28513

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Appliance 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.2 LTS

10.0
CVE-2023-3765

Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.

4.3
CVE-2023-35900

IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.4 and 23.0.0 through 23.0.5 is vulnerable to disclosi

4.3
CVE-2023-35898

IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insec

5.5
CVE-2023-37143

ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function BackwardPass::IsEmpty

5.5
CVE-2023-37142

ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::H

5.5
CVE-2023-37141

ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers:

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started