Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 190/380
8.8
CVE-2022-37975

Windows Group Policy Elevation of Privilege Vulnerability

6.5
CVE-2022-37974

Windows Mixed Reality Developer Tools Information Disclosure Vulnerability

7.7
CVE-2022-37973

Windows Local Session Manager (LSM) Denial of Service Vulnerability

7.1
CVE-2022-37971

Microsoft Windows Defender Elevation of Privilege Vulnerability

7.8
CVE-2022-37970

Windows DWM Core Library Elevation of Privilege Vulnerability

10.0
CVE-2022-37968

Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters.

5.9
CVE-2022-37965

Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

6.2
CVE-2022-35829

Service Fabric Explorer Spoofing Vulnerability

6.5
CVE-2022-35770

Windows NTLM Spoofing Vulnerability

7.5
CVE-2022-34689

Windows CryptoAPI Spoofing Vulnerability

7.5
CVE-2022-33645

Windows TCP/IP Driver Denial of Service Vulnerability

7.8
CVE-2022-33635

Windows GDI+ Remote Code Execution Vulnerability

8.1
CVE-2022-33634

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2022-30198

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2022-24504

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2022-22035

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

7.8
CVE-2022-41749

An origin validation error vulnerability in Trend Micro Apex One agents could allow a local attacker to escalate privile

6.7
CVE-2022-41748

A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local a

7.8
CVE-2022-41747

An improper certification validation vulnerability in Trend Micro Apex One agents could allow a local attacker to load a

9.1
CVE-2022-41746

A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on a

7.0
CVE-2022-41745

An Out-of-Bounds access vulnerability in Trend Micro Apex One could allow a local attacker to create a specially crafted

7.0
CVE-2022-41744

A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One Vulnerability Protection integrated component coul

7.8
CVE-2022-39959

Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini fol

6.5
CVE-2022-41291

IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user

6.5
CVE-2022-36772

IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should onl

5.5
CVE-2022-26238

The default privileges for the running service Normand Service Manager in Beckman Coulter Remisol Advance v2.0.12.1 and

5.5
CVE-2022-26236

The default privileges for the running service Normand Remisol Advance Launcher in Beckman Coulter Remisol Advance v2.0.

6.5
CVE-2022-41294

IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing

6.1
CVE-2022-38709

IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 for Cloud Pak is vulnerable to cross-site scripting. This vuln

5.3
CVE-2022-36774

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulatio

6.5
CVE-2022-26240

The default privileges for the running service Normand Message Buffer in Beckman Coulter Remisol Advance v2.0.12.1 and p

5.5
CVE-2022-26239

The default privileges for the running service Normand License Manager in Beckman Coulter Remisol Advance v2.0.12.1 and

5.5
CVE-2022-26237

The default privileges for the running service Normand Viewer Service in Beckman Coulter Remisol Advance v2.0.12.1 and p

8.0
CVE-2022-41082 KEV

Microsoft Exchange Server Remote Code Execution Vulnerability

8.8
CVE-2022-41040 KEV

Microsoft Exchange Server Elevation of Privilege Vulnerability

7.8
CVE-2022-41975

RealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI inst

9.8
CVE-2022-2778

In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.

7.8
CVE-2022-40710

A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could

3.3
CVE-2022-40709

An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows

3.3
CVE-2022-40708

An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows

3.3
CVE-2022-40707

An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows

7.5
CVE-2022-40082

Hertz v0.3.0 ws discovered to contain a path traversal vulnerability via the normalizePath function.

6.5
CVE-2022-2856 KEV

Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remo

5.4
CVE-2022-40748

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a

5.4
CVE-2022-35721

IBM Jazz for Service Management 1.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to e

4.7
CVE-2022-29800

A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists bec

5.5
CVE-2022-29799

A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the Operational

7.5
CVE-2022-37972

Microsoft Endpoint Configuration Manager Spoofing Vulnerability

8.8
CVE-2022-23767

This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also i

7.8
CVE-2022-23766

An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started