Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 213/380
7.8
CVE-2022-23299

Windows PDEV Elevation of Privilege Vulnerability

7.0
CVE-2022-23298

Windows NT OS Kernel Elevation of Privilege Vulnerability

5.5
CVE-2022-23297

Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability

7.8
CVE-2022-23296

Windows Installer Elevation of Privilege Vulnerability

7.8
CVE-2022-23295

Raw Image Extension Remote Code Execution Vulnerability

8.8
CVE-2022-23294

Windows Event Tracing Remote Code Execution Vulnerability

7.8
CVE-2022-23293

Windows Fast FAT File System Driver Elevation of Privilege Vulnerability

7.8
CVE-2022-23291

Windows DWM Core Library Elevation of Privilege Vulnerability

7.8
CVE-2022-23290

Windows Inking COM Elevation of Privilege Vulnerability

7.0
CVE-2022-23288

Windows DWM Core Library Elevation of Privilege Vulnerability

7.0
CVE-2022-23287

Windows ALPC Elevation of Privilege Vulnerability

7.0
CVE-2022-23286

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

8.8
CVE-2022-23285

Remote Desktop Client Remote Code Execution Vulnerability

7.2
CVE-2022-23284

Windows Print Spooler Elevation of Privilege Vulnerability

7.0
CVE-2022-23283

Windows ALPC Elevation of Privilege Vulnerability

7.8
CVE-2022-23282

Paint 3D Remote Code Execution Vulnerability

5.5
CVE-2022-23281

Windows Common Log File System Driver Information Disclosure Vulnerability

5.9
CVE-2022-23278

Microsoft Defender for Endpoint Spoofing Vulnerability

8.8
CVE-2022-23277

Microsoft Exchange Server Remote Code Execution Vulnerability

7.8
CVE-2022-23266

Microsoft Defender for IoT Elevation of Privilege Vulnerability

7.2
CVE-2022-23265

Microsoft Defender for IoT Remote Code Execution Vulnerability

6.5
CVE-2022-23253

Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

4.4
CVE-2022-22010

Media Foundation Information Disclosure Vulnerability

7.8
CVE-2022-22007

HEVC Video Extensions Remote Code Execution Vulnerability

7.8
CVE-2022-22006

HEVC Video Extensions Remote Code Execution Vulnerability

8.8
CVE-2022-21990

Remote Desktop Client Remote Code Execution Vulnerability

3.3
CVE-2022-21977

Media Foundation Information Disclosure Vulnerability

4.7
CVE-2022-21975

Windows Hyper-V Denial of Service Vulnerability

5.5
CVE-2022-21973

Windows Media Center Update Denial of Service Vulnerability

7.0
CVE-2022-21967

Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability

5.5
CVE-2021-46702

Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers to

8.1
CVE-2021-26617

This issues due to insufficient verification of the various input values from user’s input. The vulnerability allows rem

7.5
CVE-2022-25331

Uncaught exceptions that can be generated in Trend Micro ServerProtection 6.0/5.8 Information Server could allow a remot

9.8
CVE-2022-25330

Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote atta

9.8
CVE-2022-25329

Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific

7.8
CVE-2022-24680

A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Se

7.8
CVE-2022-24679

A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Se

7.5
CVE-2022-24678

An security agent resource exhaustion denial-of-service vulnerability in Trend Micro Apex One, Trend Micro Apex One as a

5.3
CVE-2022-0564

A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An

7.8
CVE-2022-25372

Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWN

7.8
CVE-2022-25365

Docker Desktop before 4.5.1 on Windows allows attackers to move arbitrary files. NOTE: this issue exists because of an i

6.1
CVE-2022-25256

SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel

8.8
CVE-2022-24971

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.

8.8
CVE-2022-24369

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.

6.5
CVE-2022-24368

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Read

8.8
CVE-2022-24367

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.

8.8
CVE-2022-24366

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.

8.8
CVE-2022-24365

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.

8.8
CVE-2022-24364

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.

8.8
CVE-2022-24363

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started