Microsoft
91,472 known vulnerabilities
Top Products
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resu
After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path
Microsoft Outlook Denial of Service Vulnerability
Windows Local Security Authority (LSA) Denial of Service Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
Unified Write Filter Elevation of Privilege Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Hyper-V Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Windows Digital Media Receiver Elevation of Privilege Vulnerability
HTTP.sys Denial of Service Vulnerability
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
Windows Digital Media Receiver Elevation of Privilege Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
An issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any typ
An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system
An issue was discovered in Faronics Insight 10.0.19045 on Windows. Every keystroke made by any user on a computer with t
An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized be
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a crafted pr
An issue was discovered in Faronics Insight 10.0.19045 on Windows. A suitably positioned attacker could perform a man-in
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-c
An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate w
An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the t
An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauth
Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated m
Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22.
A vulnerability, which was classified as problematic, has been found in Twister Antivirus 8. This issue affects the func
A vulnerability classified as critical was found in Twister Antivirus 8. This vulnerability affects the function 0x804f2
IBM InfoSphere Information Server 11.7 is affected by a remote code execution vulnerability due to insecure deserializat
IBM MQ 8.0, 9.0, 9.1, 9.2, and 9.3 could disclose sensitive user information from a trace file if that functionality has
IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to
IBM InfoSphere Information Server 11.7 stores user credentials in plain clear text which can be read by a local user. I
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ
IBM MQ 8.0, 9.0, and 9.1 could allow a local user to obtain sensitive credential information when a detailed technical e
Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53
Azure Arc Jumpstart Information Disclosure Vulnerability
Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acron
Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agen
Sensitive information disclosure and manipulation due to improper certification validation. The following products are a
Sensitive information disclosure and manipulation due to improper certification validation. The following products are a
TLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) befor
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windo
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started