Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 166/380
7.8
CVE-2023-25515

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where unexpected untrusted data is parsed, w

6.7
CVE-2023-28065

Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Wind

6.3
CVE-2023-28071

Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on

7.5
CVE-2023-33141

Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability

8.6
CVE-2023-35174

Livebook is a web application for writing interactive and collaborative code notebooks. On Windows, it is possible to op

6.2
CVE-2023-33842

IBM SPSS Modeler on Windows 17.0, 18.0, 18.2.2, 18.3, 18.4, and 18.5 requires the end user to have access to the server

8.4
CVE-2023-28956

IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to escalate their privileges

9.8
CVE-2023-29542

A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious fil

7.5
CVE-2023-32214

Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attac

5.5
CVE-2023-29532

A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service

7.8
CVE-2023-28295

Microsoft Publisher Remote Code Execution Vulnerability

7.8
CVE-2023-28287

Microsoft Publisher Remote Code Execution Vulnerability

7.8
CVE-2023-32028

Microsoft SQL OLE DB Remote Code Execution Vulnerability

7.8
CVE-2023-32027

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

7.8
CVE-2023-32026

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

7.8
CVE-2023-32025

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

7.8
CVE-2023-29356

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

7.8
CVE-2023-29349

Microsoft ODBC and OLE DB Remote Code Execution Vulnerability

7.0
CVE-2022-4149

The Netskope client service (prior to R96) on Windows runs as NT AUTHORITY\SYSTEM which writes log files to a writable d

7.0
CVE-2023-2270

The Netskope client service running with NT\SYSTEM privileges accepts network connections from localhost to start variou

6.5
CVE-2023-34367

Windows 7 is vulnerable to a full blind TCP/IP hijacking attack. The vulnerability exists in Windows 7 (any Windows unti

8.8
CVE-2023-32031

Microsoft Exchange Server Remote Code Execution Vulnerability

7.5
CVE-2023-32030

.NET and Visual Studio Denial of Service Vulnerability

3.0
CVE-2023-32024

Microsoft Power Apps Spoofing Vulnerability

7.1
CVE-2023-29337

NuGet Client Remote Code Execution Vulnerability

7.5
CVE-2023-29331

.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

7.8
CVE-2023-29326

.NET Framework Remote Code Execution Vulnerability

8.0
CVE-2023-28310

Microsoft Exchange Server Remote Code Execution Vulnerability

7.5
CVE-2023-24936

.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability

7.8
CVE-2023-24897

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

7.8
CVE-2023-24895

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

6.6
CVE-2023-0837

An improper authorization check of local device settings in TeamViewer Remote between version 15.41 and 15.42.7 for Win

6.5
CVE-2023-24937

Windows CryptoAPI Denial of Service Vulnerability

7.8
CVE-2023-33146

Microsoft Office Remote Code Execution Vulnerability

6.5
CVE-2023-33145

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

6.6
CVE-2023-33144

Visual Studio Code Spoofing Vulnerability

6.5
CVE-2023-33142

Microsoft SharePoint Server Elevation of Privilege Vulnerability

6.5
CVE-2023-33140

Microsoft OneNote Spoofing Vulnerability

5.5
CVE-2023-33139

Visual Studio Information Disclosure Vulnerability

7.8
CVE-2023-33137

Microsoft Excel Remote Code Execution Vulnerability

7.3
CVE-2023-33135

.NET and Visual Studio Elevation of Privilege Vulnerability

7.8
CVE-2023-33133

Microsoft Excel Remote Code Execution Vulnerability

6.3
CVE-2023-33132

Microsoft SharePoint Server Spoofing Vulnerability

8.8
CVE-2023-33131

Microsoft Outlook Remote Code Execution Vulnerability

7.3
CVE-2023-33130

Microsoft SharePoint Server Spoofing Vulnerability

6.5
CVE-2023-33129

Microsoft SharePoint Server Denial of Service Vulnerability

7.3
CVE-2023-33128

.NET and Visual Studio Remote Code Execution Vulnerability

7.3
CVE-2023-33126

.NET and Visual Studio Remote Code Execution Vulnerability

6.5
CVE-2023-32032

.NET and Visual Studio Elevation of Privilege Vulnerability

7.8
CVE-2023-32029

Microsoft Excel Remote Code Execution Vulnerability

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started