Microsoft
91,472 known vulnerabilities
Top Products
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over
Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security f
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex
Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex
Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex
Audition is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attack
Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex
Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized at
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to ele
Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows a
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Com
Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privilege
Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to pe
Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges ove
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical atta
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service ove
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate p
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.
Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.
Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.
Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges local
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privile
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started