Microsoft
91,472 known vulnerabilities
Top Products
When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firef
A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal
Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.
VMware Tools for Windows (11.x.y prior to 11.3.0) contains a denial-of-service vulnerability in the VM3DMP driver. A mal
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.
PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname.
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as
IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users i
IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted
TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.
A heap information leak/kernel pool address disclosure vulnerability in the AMD Graphics Driver for Windows 10 may lead
An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may cause arbitrary code exec
An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of pri
An out of bounds write vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privileges or d
An invalid object pointer free vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privile
An insufficient input validation in the AMD Graphics Driver for Windows 10 may allow unprivileged users to unload the dr
An out of bounds write and read vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privil
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using
ripgrep before 13 on Windows allows attackers to trigger execution of arbitrary programs from the current working direct
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe
A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that e
Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticate
Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
Windows MSHTML Platform Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft DWM Core Library Elevation of Privilege Vulnerability
Microsoft Defender Remote Code Execution Vulnerability
Paint 3D Remote Code Execution Vulnerability
Microsoft Intune Management Extension Remote Code Execution Vulnerability
Microsoft Defender Denial of Service Vulnerability
Windows Hyper-V Denial of Service Vulnerability
Server for NFS Information Disclosure Vulnerability
Server for NFS Information Disclosure Vulnerability
Server for NFS Denial of Service Vulnerability
Windows GPSVC Elevation of Privilege Vulnerability
Event Tracing for Windows Information Disclosure Vulnerability
Windows HTML Platforms Security Feature Bypass Vulnerability
Windows TCP/IP Driver Security Feature Bypass Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Remote Desktop Services Denial of Service Vulnerability
VP9 Video Extensions Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Information Disclosure Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
Kerberos AppContainer Security Feature Bypass Vulnerability
Windows Bind Filter Driver Information Disclosure Vulnerability
Scripting Engine Memory Corruption Vulnerability
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started