Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 17/380
8.0
CVE-2026-50683

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent n

7.1
CVE-2026-50682

Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.

5.5
CVE-2026-50681

Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attack

8.2
CVE-2026-50680

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50679

Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges loc

7.8
CVE-2026-50677

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50676

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a

7.0
CVE-2026-50674

Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50673

Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-50672

Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-50670

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-50669

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service

6.8
CVE-2026-50668

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.

7.8
CVE-2026-50667

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an au

8.8
CVE-2026-50666

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a ne

7.8
CVE-2026-50665

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

6.1
CVE-2026-50661

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph

7.0
CVE-2026-50658

Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privile

4.7
CVE-2026-50657

Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to

7.8
CVE-2026-50655

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

7.5
CVE-2026-50647

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unautho

9.8
CVE-2026-50518

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

7.8
CVE-2026-50510

Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute

7.8
CVE-2026-50509

Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate

7.5
CVE-2026-50505

Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.

6.5
CVE-2026-50504

Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

7.0
CVE-2026-50503

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an

8.0
CVE-2026-50502

Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute cod

7.8
CVE-2026-50501

Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code loca

7.5
CVE-2026-50500

Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.

7.8
CVE-2026-50499

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges local

7.8
CVE-2026-50498

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

6.5
CVE-2026-50497

Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a netwo

7.5
CVE-2026-50496

Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a

6.1
CVE-2026-50495

Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

7.8
CVE-2026-50494

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

7.8
CVE-2026-50493

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

6.8
CVE-2026-50492

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with

7.0
CVE-2026-50491

Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-50490

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-50489

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50488

Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service al

8.1
CVE-2026-50487

Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.

7.8
CVE-2026-50486

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

4.5
CVE-2026-50485

Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.

7.8
CVE-2026-50484

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

5.5
CVE-2026-50483

Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker

7.3
CVE-2026-50482

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

7.8
CVE-2026-50480

Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate

7.8
CVE-2026-50479

Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started