Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 168/380
7.5
CVE-2023-33143

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

6.5
CVE-2023-25738

Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resu

8.1
CVE-2023-25734

After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path

7.5
CVE-2022-35742

Microsoft Outlook Denial of Service Vulnerability

6.5
CVE-2022-35759

Windows Local Security Authority (LSA) Denial of Service Vulnerability

5.5
CVE-2022-35758

Windows Kernel Memory Information Disclosure Vulnerability

7.3
CVE-2022-35757

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

7.8
CVE-2022-35756

Windows Kerberos Elevation of Privilege Vulnerability

7.3
CVE-2022-35755

Windows Print Spooler Elevation of Privilege Vulnerability

6.7
CVE-2022-35754

Unified Write Filter Elevation of Privilege Vulnerability

8.1
CVE-2022-35753

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

8.1
CVE-2022-35752

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

7.8
CVE-2022-35751

Windows Hyper-V Elevation of Privilege Vulnerability

7.8
CVE-2022-35750

Win32k Elevation of Privilege Vulnerability

7.8
CVE-2022-35749

Windows Digital Media Receiver Elevation of Privilege Vulnerability

7.5
CVE-2022-35748

HTTP.sys Denial of Service Vulnerability

5.9
CVE-2022-35747

Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability

7.8
CVE-2022-35746

Windows Digital Media Receiver Elevation of Privilege Vulnerability

8.1
CVE-2022-35745

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

9.8
CVE-2022-35744

Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability

7.8
CVE-2022-35743

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

8.8
CVE-2023-28353

An issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any typ

7.4
CVE-2023-28352

An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system

3.3
CVE-2023-28351

An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with t

6.1
CVE-2023-28350

An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized be

8.8
CVE-2023-28349

An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted pr

7.4
CVE-2023-28348

An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in

9.6
CVE-2023-28347

An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-c

7.3
CVE-2023-28346

An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate w

4.6
CVE-2023-28345

An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the t

7.1
CVE-2023-28344

An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauth

7.8
CVE-2023-2939

Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to

6.1
CVE-2023-20884

VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated m

8.8
CVE-2023-2984

Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22.

5.5
CVE-2023-2874

A vulnerability, which was classified as problematic, has been found in Twister Antivirus 8. This issue affects the func

5.3
CVE-2023-2873

A vulnerability classified as critical was found in Twister Antivirus 8. This vulnerability affects the function 0x804f2

8.8
CVE-2023-32336

IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserializat

5.1
CVE-2023-28950

IBM MQ 8.0, 9.0, 9.1, 9.2, and 9.3 could disclose sensitive user information from a trace file if that functionality has

5.5
CVE-2023-28529

IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to

6.2
CVE-2023-22878

IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read by a local user. I

6.3
CVE-2022-47984

IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ

6.2
CVE-2023-28514

IBM MQ 8.0, 9.0, and 9.1 could allow a local user to obtain sensitive credential information when a detailed technical e

7.8
CVE-2023-33240

Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53

3.3
CVE-2022-35798

Azure Arc Jumpstart Information Disclosure Vulnerability

7.8
CVE-2022-4418

Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acron

7.5
CVE-2022-45459

Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agen

7.5
CVE-2022-45458

Sensitive information disclosure and manipulation due to improper certification validation. The following products are a

7.5
CVE-2022-45457

Sensitive information disclosure and manipulation due to improper certification validation. The following products are a

7.5
CVE-2022-45453

TLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) befor

7.8
CVE-2022-45452

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windo

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started