Microsoft
91,472 known vulnerabilities
Top Products
A Local File Inclusion vulnerability has been found in Axiell Iguana CMS. Due to insufficient neutralisation of user inp
A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's br
A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's br
A vulnerability has been found in AlliedModders AMX Mod X on Windows and classified as critical. This vulnerability affe
Inappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attac
NVIDIA GPU Display Driver for Windows contains a vulnerability where a regular user can cause an out-of-bounds read, whi
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkD
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkD
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler, where im
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged
NVIDIA Control Panel for Windows contains a vulnerability where an unauthorized user or an unprivileged regular user can
NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular use
Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. Af
Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypas
Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall ac
A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2. Affected is an unkno
A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated
A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-p
A link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One a
BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix ope
When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to une
IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify
The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applica
When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly bein
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write a
By generally accepting and passing resource handles across processes, a compromised content process might have confused
A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window s
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This c
aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of
IBM Spectrum Control 5.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hig
Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Clo
In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-d
Improper preservation of permissions vulnerability in Trellix Endpoint Agent (xAgent) prior to V35.31.22 on Windows allo
Adobe Illustrator versions 26.5.1 (and earlier), and 27.0 (and earlier) are affected by an out-of-bounds read vulnerabil
Adobe Illustrator versions 26.5.1 (and earlier), and 27.0 (and earlier) are affected by an out-of-bounds read vulnerabil
Adobe Illustrator versions 26.5.1 (and earlier), and 27.0 (and earlier) are affected by an out-of-bounds read vulnerabil
Adobe Illustrator versions 26.5.1 (and earlier), and 27.0 (and earlier) are affected by an out-of-bounds read vulnerabil
Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF)
VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. VMware ha
Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the u
Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft Office Graphics Remote Code Execution Vulnerability
Microsoft Outlook for Mac Spoofing Vulnerability
DirectX Graphics Kernel Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Windows Kernel Denial of Service Vulnerability
Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability
Windows Terminal Remote Code Execution Vulnerability
Azure Network Watcher Agent Security Feature Bypass Vulnerability
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started