Microsoft
91,472 known vulnerabilities
Top Products
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vulnerability
Azure DevOps Server Cross-Site Scripting Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft SQL Server Remote Code Execution Vulnerability
Local privilege escalation due to incomplete uninstallation cleanup. The following products are affected: Acronis Cyber
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent
IBM App Connect Enterprise 11.0.0.8 through 11.0.0.19 and 12.0.1.0 through 12.0.5.0 is vulnerable to a buffer overflow.
IBM MQ 8.0.0, 9.0.0, 9.1.0, 9.2.0, 9.3.0 Managed File Transfer could allow a local user to obtain sensitive information
NVIDIA GeForce Experience contains a vulnerability in the NVContainer component, where a user without administrator pri
HP Factory Preinstalled Images on certain systems that shipped with Windows 10 versions 20H2 and earlier OS versions mig
IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally
A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching
External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in Yuga
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged
IBM Infosphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a
IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptogr
IBM Sterling Secure Proxy 6.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the H
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user
An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local syste
NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experie
NVIDIA GeForce Experience contains an uncontrolled search path vulnerability in all its client installers, where an att
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication
IBM App Connect Enterprise 11.0.0.17 through 11.0.0.19 and 12.0.4.0 and 12.0.5.0 contains an unspecified vulnerability
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the
VMware Workstation contains an arbitrary file deletion vulnerability. A malicious actor with local user privileges on th
The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local use
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local att
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege e
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution w
A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionali
On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sen
WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be abl
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are
Razer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege
A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By craf
SoftPerfect NetWorx 7.1.1 on Windows allows an attacker to execute a malicious binary with potentially higher privileges
IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryptographic keys that co
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged
An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which co
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started