Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 187/380
7.8
CVE-2022-41093

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

7.8
CVE-2022-41092

Windows Win32k Elevation of Privilege Vulnerability

5.4
CVE-2022-41091 KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

5.9
CVE-2022-41090

Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

8.1
CVE-2022-41088

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

6.4
CVE-2022-41086

Windows Group Policy Elevation of Privilege Vulnerability

7.5
CVE-2022-41085

Azure CycleCloud Elevation of Privilege Vulnerability

8.8
CVE-2022-41080 KEV

Microsoft Exchange Server Elevation of Privilege Vulnerability

8.0
CVE-2022-41079

Microsoft Exchange Server Spoofing Vulnerability

8.0
CVE-2022-41078

Microsoft Exchange Server Spoofing Vulnerability

7.8
CVE-2022-41073 KEV

Windows Print Spooler Elevation of Privilege Vulnerability

4.4
CVE-2022-41066

Microsoft Dynamics Business Central Information Disclosure Vulnerability

5.8
CVE-2022-41064

.NET Framework Information Disclosure Vulnerability

7.8
CVE-2022-41063

Microsoft Excel Remote Code Execution Vulnerability

8.8
CVE-2022-41062

Microsoft SharePoint Server Remote Code Execution Vulnerability

7.8
CVE-2022-41061

Microsoft Word Remote Code Execution Vulnerability

5.5
CVE-2022-41060

Microsoft Word Information Disclosure Vulnerability

7.5
CVE-2022-41058

Windows Network Address Translation (NAT) Denial of Service Vulnerability

7.8
CVE-2022-41057

Windows HTTP.sys Elevation of Privilege Vulnerability

7.5
CVE-2022-41056

Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability

5.5
CVE-2022-41055

Windows Human Interface Device Information Disclosure Vulnerability

7.8
CVE-2022-41054

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

7.5
CVE-2022-41053

Windows Kerberos Denial of Service Vulnerability

7.8
CVE-2022-41052

Windows Graphics Component Remote Code Execution Vulnerability

7.8
CVE-2022-41051

Azure RTOS GUIX Studio Remote Code Execution Vulnerability

7.8
CVE-2022-41050

Windows Extensible File Allocation Table Elevation of Privilege Vulnerability

5.4
CVE-2022-41049 KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

8.8
CVE-2022-41048

Microsoft ODBC Driver Remote Code Execution Vulnerability

8.8
CVE-2022-41047

Microsoft ODBC Driver Remote Code Execution Vulnerability

7.8
CVE-2022-41045

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

8.1
CVE-2022-41044

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2022-41039

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2022-38023

Netlogon RPC Elevation of Privilege Vulnerability

6.5
CVE-2022-38015

Windows Hyper-V Denial of Service Vulnerability

7.0
CVE-2022-38014

Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability

7.8
CVE-2022-37992

Windows Group Policy Elevation of Privilege Vulnerability

7.2
CVE-2022-37967

Windows Kerberos Elevation of Privilege Vulnerability

8.1
CVE-2022-37966

Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability

7.5
CVE-2022-27674

Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks pote

7.5
CVE-2022-23831

Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading

5.5
CVE-2022-41205

SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attack

5.6
CVE-2022-39343

Azure RTOS FileX is a FAT-compatible file system that’s fully integrated with Azure RTOS ThreadX. In versions before 6.2

7.2
CVE-2022-36077

The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions p

6.5
CVE-2022-2188

Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated priv

9.8
CVE-2022-39344

Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS Thre

9.1
CVE-2022-40747

"IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing X

6.5
CVE-2022-40235

"IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run j

5.9
CVE-2022-38712

"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduc

5.3
CVE-2022-38710

IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version to an unauthorized control sphere info

7.8
CVE-2022-35717

"IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on th

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started