Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 233/380
7.6
CVE-2021-36940

Microsoft SharePoint Server Spoofing Vulnerability

5.5
CVE-2021-36938

Windows Cryptographic Primitives Library Information Disclosure Vulnerability

7.8
CVE-2021-36937

Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability

8.8
CVE-2021-36936

Windows Print Spooler Remote Code Execution Vulnerability

7.5
CVE-2021-36933

Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability

7.5
CVE-2021-36932

Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability

7.8
CVE-2021-36927

Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability

7.5
CVE-2021-36926

Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability

7.8
CVE-2021-34537

Windows Bluetooth Driver Elevation of Privilege Vulnerability

7.8
CVE-2021-34536

Windows Storage Spaces Controller Elevation of Privilege Vulnerability

8.8
CVE-2021-34535

Remote Desktop Client Remote Code Execution Vulnerability

6.8
CVE-2021-34534

Windows MSHTML Platform Remote Code Execution Vulnerability

7.8
CVE-2021-34533

Windows Graphics Component Font Parsing Remote Code Execution Vulnerability

5.5
CVE-2021-34532

ASP.NET Core and Visual Studio Information Disclosure Vulnerability

7.8
CVE-2021-34530

Windows Graphics Component Remote Code Execution Vulnerability

8.1
CVE-2021-34524

Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability

7.0
CVE-2021-34487

Windows Event Tracing Elevation of Privilege Vulnerability

7.8
CVE-2021-34486 KEV

Windows Event Tracing Elevation of Privilege Vulnerability

5.0
CVE-2021-34485

.NET Core and Visual Studio Information Disclosure Vulnerability

7.8
CVE-2021-34484 KEV

Windows User Profile Service Elevation of Privilege Vulnerability

7.8
CVE-2021-34483

Windows Print Spooler Elevation of Privilege Vulnerability

6.8
CVE-2021-34480

Scripting Engine Memory Corruption Vulnerability

7.8
CVE-2021-34478

Microsoft Office Remote Code Execution Vulnerability

7.8
CVE-2021-34471

Microsoft Defender Elevation of Privilege Vulnerability

7.0
CVE-2021-33762

Azure CycleCloud Elevation of Privilege Vulnerability

7.5
CVE-2021-26433

Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability

9.8
CVE-2021-26432

Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability

7.8
CVE-2021-26431

Windows Recovery Environment Agent Elevation of Privilege Vulnerability

6.0
CVE-2021-26430

Azure Sphere Denial of Service Vulnerability

7.7
CVE-2021-26429

Azure Sphere Elevation of Privilege Vulnerability

4.4
CVE-2021-26428

Azure Sphere Information Disclosure Vulnerability

7.0
CVE-2021-26426

Windows User Account Profile Picture Elevation of Privilege Vulnerability

7.8
CVE-2021-26425

Windows Event Tracing Elevation of Privilege Vulnerability

9.9
CVE-2021-26424

Windows TCP/IP Remote Code Execution Vulnerability

7.5
CVE-2021-26423

.NET Core and Visual Studio Denial of Service Vulnerability

7.8
CVE-2021-38088

Acronis Cyber Protect 15 for Windows prior to build 27009 allowed local privilege escalation via binary hijacking.

7.8
CVE-2021-38086

Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed loc

7.8
CVE-2021-38571

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and

7.8
CVE-2021-0062

Improper input validation in some Intel(R) Graphics Drivers before version 27.20.100.8935 may allow an authenticated use

7.8
CVE-2021-0061

Improper initialization in some Intel(R) Graphics Driver before version 27.20.100.9030 may allow an authenticated user t

5.5
CVE-2021-0012

Use after free in some Intel(R) Graphics Driver before version 27.20.100.8336, 15.45.33.5164, and 15.40.47.5166 may allo

9.8
CVE-2021-26606

A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability i

7.5
CVE-2021-26605

An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. T

3.5
CVE-2021-33597

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the SAVAPI component used in certain F

7.8
CVE-2021-34853

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34852

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34851

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34850

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34849

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34848

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started