Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 193/380
8.8
CVE-2022-35823

Microsoft SharePoint Remote Code Execution Vulnerability

8.8
CVE-2022-35805

Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability

7.8
CVE-2022-35803

Windows Common Log File System Driver Elevation of Privilege Vulnerability

8.8
CVE-2022-34734

Microsoft ODBC Driver Remote Code Execution Vulnerability

8.8
CVE-2022-34733

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

8.8
CVE-2022-34732

Microsoft ODBC Driver Remote Code Execution Vulnerability

8.8
CVE-2022-34731

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

8.8
CVE-2022-34730

Microsoft ODBC Driver Remote Code Execution Vulnerability

7.8
CVE-2022-34729

Windows GDI Elevation of Privilege Vulnerability

5.5
CVE-2022-34728

Windows Graphics Component Information Disclosure Vulnerability

8.8
CVE-2022-34727

Microsoft ODBC Driver Remote Code Execution Vulnerability

8.8
CVE-2022-34726

Microsoft ODBC Driver Remote Code Execution Vulnerability

7.0
CVE-2022-34725

Windows ALPC Elevation of Privilege Vulnerability

7.5
CVE-2022-34724

Windows DNS Server Denial of Service Vulnerability

5.5
CVE-2022-34723

Windows DPAPI (Data Protection Application Programming Interface) Information Disclosure Vulnerability

9.8
CVE-2022-34722

Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability

9.8
CVE-2022-34721

Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability

7.5
CVE-2022-34720

Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability

7.8
CVE-2022-34719

Windows Distributed File System (DFS) Elevation of Privilege Vulnerability

9.8
CVE-2022-34718

Windows TCP/IP Remote Code Execution Vulnerability

8.8
CVE-2022-34700

Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability

8.1
CVE-2022-33679

Windows Kerberos Elevation of Privilege Vulnerability

8.1
CVE-2022-33647

Windows Kerberos Elevation of Privilege Vulnerability

7.8
CVE-2022-30200

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

8.2
CVE-2022-30196

Windows Secure Channel Denial of Service Vulnerability

7.3
CVE-2022-30170

Windows Credential Roaming Service Elevation of Privilege Vulnerability

7.8
CVE-2022-26929

.NET Framework Remote Code Execution Vulnerability

7.0
CVE-2022-26928

Windows Photo Import API Elevation of Privilege Vulnerability

5.4
CVE-2022-34165

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22

5.0
CVE-2022-36088

GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to

7.3
CVE-2022-36070

Poetry is a dependency manager for Python. To handle dependencies that come from a Git repository, Poetry executes vario

6.7
CVE-2022-37771

IObit Malware Fighter v9.2 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administ

5.9
CVE-2022-23678

A vulnerability in the Aruba Virtual Intranet Access (VIA) client for Microsoft Windows operating system client communic

7.2
CVE-2022-34883

OS Command Injection vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users

9.0
CVE-2022-34882

Information Exposure Through an Error Message vulnerability in Hitachi RAID Manager Storage Replication Adapter allows r

6.5
CVE-2022-28199

NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where

7.8
CVE-2022-37173

An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacki

8.8
CVE-2022-36564

Incorrect access control in the install directory (C:\Strawberry) of StrawberryPerl v5.32.1.1 and below allows authentic

6.5
CVE-2022-2330

Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows

5.5
CVE-2022-25641

Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference inf

7.8
CVE-2021-41785

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-

7.8
CVE-2021-41784

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-

7.8
CVE-2021-41783

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-

7.8
CVE-2021-41782

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-

7.8
CVE-2021-41781

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-

7.8
CVE-2021-41780

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-

5.5
CVE-2021-40326

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental

6.7
CVE-2022-34303

A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with

6.7
CVE-2022-34302

A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or

6.7
CVE-2022-34301

A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass o

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started