Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 225/380
7.4
CVE-2021-37980

Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially

5.5
CVE-2021-41023

A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated

7.8
CVE-2021-41022

A improper privilege management in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows attacker to execute p

9.1
CVE-2021-38948

IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XM

8.8
CVE-2021-29888

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to exec

5.4
CVE-2021-29771

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a

5.4
CVE-2021-29738

IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery

7.5
CVE-2021-29737

IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of

7.5
CVE-2020-7875

DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and e

7.2
CVE-2021-26610

The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upl

8.1
CVE-2021-26607

An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary com

7.8
CVE-2020-28963

Passcovery Co. Ltd ZIP Password Recovery v3.70.69.0 was discovered to contain a buffer overflow via the decompress funct

7.8
CVE-2021-30359

The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps duri

7.8
CVE-2021-42108

Unnecessary privilege vulnerabilities in the Web Console of Trend Micro Apex One, Apex One as a Service and Worry-Free B

7.8
CVE-2021-42107

Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0

7.8
CVE-2021-42106

Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0

7.8
CVE-2021-42105

Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0

7.8
CVE-2021-42104

Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0

7.8
CVE-2021-42103

An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a loca

7.8
CVE-2021-42102

An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow

7.8
CVE-2021-42101

An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a loca

7.8
CVE-2021-42011

An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local a

7.5
CVE-2021-23139

A null pointer vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an attacker t

5.6
CVE-2021-42299

Microsoft Surface Pro 3 Security Feature Bypass Vulnerability

7.8
CVE-2021-40731

Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and

3.3
CVE-2021-40730

Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and

3.3
CVE-2021-40729

Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and

7.8
CVE-2021-40728

Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and

7.8
CVE-2021-40989

A local escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Pol

4.2
CVE-2021-41363

Intune Management Extension Security Feature Bypass Vulnerability

5.4
CVE-2021-41361

Active Directory Federation Server Spoofing Vulnerability

7.8
CVE-2021-41357 KEV

Win32k Elevation of Privilege Vulnerability

5.7
CVE-2021-41355

.NET Core and Visual Studio Information Disclosure Vulnerability

5.4
CVE-2021-41354

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

5.4
CVE-2021-41353

Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability

7.5
CVE-2021-41352

SCOM Information Disclosure Vulnerability

6.5
CVE-2021-41350

Microsoft Exchange Server Spoofing Vulnerability

8.0
CVE-2021-41348

Microsoft Exchange Server Elevation of Privilege Vulnerability

7.8
CVE-2021-41347

Windows AppX Deployment Service Elevation of Privilege Vulnerability

5.3
CVE-2021-41346

Console Window Host Security Feature Bypass Vulnerability

7.8
CVE-2021-41345

Storage Spaces Controller Elevation of Privilege Vulnerability

8.1
CVE-2021-41344

Microsoft SharePoint Server Remote Code Execution Vulnerability

5.5
CVE-2021-41343

Windows Fast FAT File System Driver Information Disclosure Vulnerability

6.8
CVE-2021-41342

Windows MSHTML Platform Remote Code Execution Vulnerability

7.8
CVE-2021-41340

Windows Graphics Component Remote Code Execution Vulnerability

4.7
CVE-2021-41339

Microsoft DWM Core Library Elevation of Privilege Vulnerability

5.5
CVE-2021-41338

Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability

4.9
CVE-2021-41337

Active Directory Security Feature Bypass Vulnerability

5.5
CVE-2021-41336

Windows Kernel Information Disclosure Vulnerability

7.8
CVE-2021-41335

Windows Kernel Elevation of Privilege Vulnerability

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started