Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 183/380
7.8
CVE-2023-21724

Microsoft DWM Core Library Elevation of Privilege Vulnerability

7.5
CVE-2023-21683

Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability

5.3
CVE-2023-21682

Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability

8.8
CVE-2023-21681

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

7.8
CVE-2023-21680

Windows Win32k Elevation of Privilege Vulnerability

8.1
CVE-2023-21679

Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability

7.8
CVE-2023-21678

Windows Print Spooler Elevation of Privilege Vulnerability

7.5
CVE-2023-21677

Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability

8.8
CVE-2023-21676

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

7.8
CVE-2023-21675

Windows Kernel Elevation of Privilege Vulnerability

8.8
CVE-2023-21674 KEV

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

6.8
CVE-2023-21563

BitLocker Security Feature Bypass Vulnerability

7.8
CVE-2023-21561

Microsoft Cryptographic Services Elevation of Privilege Vulnerability

6.6
CVE-2023-21560

Windows Boot Manager Security Feature Bypass Vulnerability

5.5
CVE-2023-21559

Windows Cryptographic Information Disclosure Vulnerability

7.8
CVE-2023-21558

Windows Error Reporting Service Elevation of Privilege Vulnerability

7.5
CVE-2023-21557

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

8.1
CVE-2023-21556

Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability

8.1
CVE-2023-21555

Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability

7.8
CVE-2023-21552

Windows GDI Elevation of Privilege Vulnerability

7.8
CVE-2023-21551

Microsoft Cryptographic Services Elevation of Privilege Vulnerability

5.5
CVE-2023-21550

Windows Cryptographic Information Disclosure Vulnerability

8.8
CVE-2023-21549

Windows SMB Witness Service Elevation of Privilege Vulnerability

8.1
CVE-2023-21548

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

7.5
CVE-2023-21547

Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability

8.1
CVE-2023-21546

Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability

8.1
CVE-2023-21543

Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability

7.0
CVE-2023-21542

Windows Installer Elevation of Privilege Vulnerability

7.8
CVE-2023-21541

Windows Task Scheduler Elevation of Privilege Vulnerability

5.5
CVE-2023-21540

Windows Cryptographic Information Disclosure Vulnerability

7.5
CVE-2023-21539

Windows Authentication Remote Code Execution Vulnerability

7.5
CVE-2023-21538

.NET Denial of Service Vulnerability

7.8
CVE-2023-21537

Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability

4.7
CVE-2023-21536

Event Tracing for Windows Information Disclosure Vulnerability

8.1
CVE-2023-21535

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

7.0
CVE-2023-21532

Windows GDI Elevation of Privilege Vulnerability

7.0
CVE-2023-21531

Azure Service Fabric Container Elevation of Privilege Vulnerability

7.5
CVE-2023-21527

Windows iSCSI Service Denial of Service Vulnerability

5.3
CVE-2023-21525

Remote Procedure Call Runtime Denial of Service Vulnerability

7.8
CVE-2023-21524

Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability

6.5
CVE-2023-0140

Inappropriate implementation in in File System API in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote a

6.5
CVE-2023-0139

Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 109.0.5414.74 allowed a rem

6.5
CVE-2023-0132

Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0.5414.74 allowed a remot

7.1
CVE-2022-4294

Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is

6.4
CVE-2023-0012

In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be abl

3.1
CVE-2022-43573

IBM Robotic Process Automation 20.12 through 21.0.6 is vulnerable to exposure of the name and email for the creator/modi

4.6
CVE-2022-41740

IBM Robotic Process Automation 20.12 through 21.0.6 could allow an attacker with physical access to the system to obtai

7.8
CVE-2022-43535

A vulnerability in the ClearPass OnGuard Windows agent could allow malicious users on a Windows instance to elevate thei

6.1
CVE-2022-34330

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to cross-site scripting. This vulnera

5.5
CVE-2022-22371

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 does not invalidate session after a password change

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started