Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 234/380
7.8
CVE-2021-34847

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34846

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34845

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34844

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34843

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34842

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34841

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34840

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34839

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34838

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34837

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34836

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34835

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34834

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34833

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34832

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.

7.8
CVE-2021-34831

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.4.37

9.8
CVE-2021-37595

In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing i

9.8
CVE-2021-37594

In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing i

8.8
CVE-2021-36004

Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability in the CoolType library. A

7.5
CVE-2021-28966

In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter w

7.5
CVE-2020-14999

A logic bug in system monitoring driver of Acronis Agent after 12.5.21540 and before 12.5.23094 allowed to bypass Window

8.8
CVE-2021-29736

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the sys

7.8
CVE-2021-36742 KEV

A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free B

8.8
CVE-2021-36741 KEV

An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free

5.4
CVE-2021-20562

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_3 and 6.1.0.0 through 6.1.0.2 vulnerable to cross-s

8.8
CVE-2020-18171

TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed cr

7.8
CVE-2020-18169

A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate

4.3
CVE-2021-29784

IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2 could allow a remote attacker to obtain sensitive information when a detailed tec

6.5
CVE-2021-29770

IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow an authenticated user to perform

4.3
CVE-2021-29769

IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) does not set the secure attribute on authoriz

5.3
CVE-2021-29767

IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 could allow a remote attacker to obtain sensitive information

5.3
CVE-2021-29766

IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensi

5.4
CVE-2021-20560

IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the click

6.5
CVE-2021-20431

IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 does not invalidate session after logout which could allow an

5.3
CVE-2021-20430

IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensi

6.5
CVE-2020-4623

IBM i2 iBase 8.9.13 could allow a local authenticated attacker to execute arbitrary code on the system, caused by a DLL

7.8
CVE-2021-36934 KEV

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple syst

7.8
CVE-2021-32463

An incorrect permission assignment denial-of-service vulnerability in Trend Micro Apex One, Apex One as a Service (SaaS)

8.8
CVE-2021-34481

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file

7.1
CVE-2021-34467

Microsoft SharePoint Server Remote Code Execution Vulnerability

5.7
CVE-2021-34466

Windows Hello Security Feature Bypass Vulnerability

7.8
CVE-2021-34464

Microsoft Defender Remote Code Execution Vulnerability

7.0
CVE-2021-34462

Windows AppX Deployment Extensions Elevation of Privilege Vulnerability

7.8
CVE-2021-34461

Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability

7.8
CVE-2021-34460

Windows Storage Spaces Controller Elevation of Privilege Vulnerability

7.8
CVE-2021-34459

Windows AppContainer Elevation Of Privilege Vulnerability

9.9
CVE-2021-34458

Windows Kernel Remote Code Execution Vulnerability

5.5
CVE-2021-34457

Windows Remote Access Connection Manager Information Disclosure Vulnerability

7.8
CVE-2021-34456

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started