Microsoft
91,472 known vulnerabilities
Top Products
Windows Group Policy Elevation of Privilege Vulnerability
Windows Mixed Reality Developer Tools Information Disclosure Vulnerability
Windows Local Session Manager (LSM) Denial of Service Vulnerability
Microsoft Windows Defender Elevation of Privilege Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters.
Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
Service Fabric Explorer Spoofing Vulnerability
Windows NTLM Spoofing Vulnerability
Windows CryptoAPI Spoofing Vulnerability
Windows TCP/IP Driver Denial of Service Vulnerability
Windows GDI+ Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
An origin validation error vulnerability in Trend Micro Apex One agents could allow a local attacker to escalate privile
A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local a
An improper certification validation vulnerability in Trend Micro Apex One agents could allow a local attacker to load a
A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on a
An Out-of-Bounds access vulnerability in Trend Micro Apex One could allow a local attacker to create a specially crafted
A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One Vulnerability Protection integrated component coul
Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini fol
IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should onl
The default privileges for the running service Normand Service Manager in Beckman Coulter Remisol Advance v2.0.12.1 and
The default privileges for the running service Normand Remisol Advance Launcher in Beckman Coulter Remisol Advance v2.0.
IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing
IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 for Cloud Pak is vulnerable to cross-site scripting. This vuln
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulatio
The default privileges for the running service Normand Message Buffer in Beckman Coulter Remisol Advance v2.0.12.1 and p
The default privileges for the running service Normand License Manager in Beckman Coulter Remisol Advance v2.0.12.1 and
The default privileges for the running service Normand Viewer Service in Beckman Coulter Remisol Advance v2.0.12.1 and p
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
RealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI inst
In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.
A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could
An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows
An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows
An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows
Hertz v0.3.0 ws discovered to contain a path traversal vulnerability via the normalizePath function.
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remo
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a
IBM Jazz for Service Management 1.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to e
A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists bec
A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the Operational
Microsoft Endpoint Configuration Manager Spoofing Vulnerability
This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also i
An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started