Microsoft
91,472 known vulnerabilities
Top Products
Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an Out-of-bounds Write vulnerability. An unauthe
Adobe Prelude version 22.1.1 (and earlier) is affected by an Out-of-bounds Write vulnerability due to insecure handling
Adobe Lightroom Classic 10.3 (and earlier) are affected by a privilege escalation vulnerability in the Offline Lightroom
Access of Memory Location After End of Buffer (CWE-788)
Access of Memory Location After End of Buffer (CWE-788
Adobe InDesign versions 16.3 (and earlier), and 16.3.1 (and earlier) is affected by an Out-of-bounds Write vulnerability
Microsoft Windows SMBv3 suffers from a null pointer dereference in versions of Windows prior to the April, 2022 patch se
Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated att
Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated att
Adobe Premiere Pro version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated atta
In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental f
RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operati
Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an exposed dangerous method vulnerability that could allo
Trend Micro Security 2022 and 2021 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure vulnerabilit
Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod
Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM.
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
An uncontrolled search path element vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local
An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local a
Trend Micro Maximum Security 2022 is vulnerable to a link following vulnerability that could allow a low privileged loca
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the
VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious act
Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing at
Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Pack
Multiple Denial-of-Service vulnerabilities was discovered in the F-Secure Atlant and in certain WithSecure products whil
Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbi
Windows Print Spooler Elevation of Privilege Vulnerability
Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows)
Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, W
Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux,
HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before bu
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber
SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkD
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkD
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ECC layer, where an unprivileged regular
NVIDIA GPU Display Driver for Windows contains a vulnerability in the DirectX11 user mode driver (nvwgf2um/x.dll), where
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged
IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, c
Prime95 30.7 build 9 suffers from a Buffer Overflow vulnerability that could lead to Remote Code Execution.
The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection. When calling t
Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds read vulnerabil
Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerabi
Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerabi
Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerabi
Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerabi
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started