Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 222/380
6.1
CVE-2021-44201

Cross-site scripting (XSS) was possible in notification pop-ups. The following products are affected: Acronis Cyber Prot

5.4
CVE-2021-44200

Self cross-site scripting (XSS) was possible on devices page. The following products are affected: Acronis Cyber Protect

5.5
CVE-2021-44199

DLL hijacking could lead to denial of service. The following products are affected: Acronis Cyber Protect 15 (Windows) b

7.8
CVE-2021-44198

DLL hijacking could lead to local privilege escalation. The following products are affected: Acronis Cyber Protect 15 (W

5.5
CVE-2021-40833

A vulnerability affecting F-Secure antivirus engine was discovered whereby unpacking UPX file can lead to denial-of-serv

7.5
CVE-2020-7881

The vulnerability function is enabled when the streamer service related to the AfreecaTV communicated through web socket

7.5
CVE-2021-34424

A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before vers

9.8
CVE-2021-34423

A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows)

4.2
CVE-2021-43221

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

3.1
CVE-2021-43220

Microsoft Edge for iOS Spoofing Vulnerability

5.5
CVE-2021-43211

Windows 10 Update Assistant Elevation of Privilege Vulnerability

3.1
CVE-2021-42308

Microsoft Edge (Chromium-based) Spoofing Vulnerability

8.1
CVE-2021-42306

An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as

5.0
CVE-2021-42297

Windows 10 Update Assistant Elevation of Privilege Vulnerability

5.3
CVE-2021-38980

IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a re

7.5
CVE-2021-38891

IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow

7.5
CVE-2021-38890

IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remot

6.3
CVE-2021-40828

Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.3.3), Python (versions prior to 1.5.1

5.5
CVE-2021-43016

Adobe InCopy version 16.4 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially

7.8
CVE-2021-43015

Adobe InCopy version 16.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a m

7.8
CVE-2021-42738

Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a

7.8
CVE-2021-42737

Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a

5.5
CVE-2021-42733

Adobe Bridge version 11.1.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a special

7.8
CVE-2021-42727

Adobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted fi

7.8
CVE-2021-40775

Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a

5.5
CVE-2021-40774

Adobe Prelude version 10.1 (and earlier) is affected by a null pointer dereference vulnerability when parsing a speciall

5.5
CVE-2021-40773

Adobe Prelude version 10.1 (and earlier) is affected by a null pointer dereference vulnerability when parsing a speciall

7.8
CVE-2021-40772

Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a

7.8
CVE-2021-40771

Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a

7.8
CVE-2021-40770

Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a

7.5
CVE-2020-7882

Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and d

5.5
CVE-2021-36003

Adobe Audition version 14.2 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a specially cr

5.4
CVE-2021-33850

There is a Cross-Site Scripting vulnerability in Microsoft Clarity version 0.3. The XSS payload executes whenever the us

3.3
CVE-2021-42525

Acrobat Animate versions 21.0.9 (and earlier)is affected by an out-of-bounds read vulnerability that could lead to discl

7.8
CVE-2021-42524

Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arb

7.8
CVE-2021-42272

Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arb

5.5
CVE-2021-40761

Adobe After Effects version 18.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a

7.8
CVE-2021-40760

Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handli

7.8
CVE-2021-40759

Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handli

7.8
CVE-2021-40758

Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handli

7.8
CVE-2021-40757

Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handli

5.5
CVE-2021-40756

Adobe After Effects version 18.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a

7.8
CVE-2021-40755

Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handli

7.8
CVE-2021-40754

Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handli

7.8
CVE-2021-40753

Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handli

7.8
CVE-2021-40752

Adobe After Effects version 18.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling

7.8
CVE-2021-40751

Adobe After Effects version 18.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling

7.8
CVE-2021-40733

Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of

7.8
CVE-2021-33063

Uncontrolled search path in the Intel(R) RealSense(TM) D400 Series UWP driver for Windows 10 before version 6.1.160.22 m

5.5
CVE-2021-0120

Improper initialization in the installer for some Intel(R) Graphics DCH Drivers for Windows 10 before version 27.20.100.

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started