Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 238/380
8.1
CVE-2021-29968

When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firef

7.1
CVE-2021-29964

A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to

6.5
CVE-2021-29951

The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal

9.8
CVE-2020-19510

Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.

5.5
CVE-2021-21997

VMware Tools for Windows (11.x.y prior to 11.3.0) contains a denial-of-service vulnerability in the VM3DMP driver. A mal

7.8
CVE-2021-31476

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.

8.1
CVE-2021-34551

PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname.

7.5
CVE-2021-29702

Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as

6.5
CVE-2021-20488

IBM Security Identity Manager 6.0.2 could allow an authenticated malicious user to change the passwords of other users i

6.5
CVE-2021-20483

IBM Security Identity Manager 6.0.2 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted

7.8
CVE-2021-34803

TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.

5.5
CVE-2020-12987

A heap information leak/kernel pool address disclosure vulnerability in the AMD Graphics Driver for Windows 10 may lead

7.8
CVE-2020-12986

An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may cause arbitrary code exec

7.8
CVE-2020-12985

An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of pri

7.8
CVE-2020-12983

An out of bounds write vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privileges or d

7.8
CVE-2020-12982

An invalid object pointer free vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privile

7.8
CVE-2020-12981

An insufficient input validation in the AMD Graphics Driver for Windows 10 may allow unprivileged users to unload the dr

7.8
CVE-2020-12980

An out of bounds write and read vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privil

8.8
CVE-2021-29754

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using

9.8
CVE-2021-3013

ripgrep before 13 on Windows allows attackers to trigger execution of arbitrary programs from the current working direct

5.4
CVE-2021-26829 KEV

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.

8.8
CVE-2021-26828 KEV

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and exe

7.8
CVE-2021-3041

A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that e

7.2
CVE-2021-20081

Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticate

5.5
CVE-2020-13938

Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows

7.5
CVE-2021-33742 KEV

Windows MSHTML Platform Remote Code Execution Vulnerability

8.2
CVE-2021-33741

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

8.4
CVE-2021-33739 KEV

Microsoft DWM Core Library Elevation of Privilege Vulnerability

7.8
CVE-2021-31985

Microsoft Defender Remote Code Execution Vulnerability

7.8
CVE-2021-31983

Paint 3D Remote Code Execution Vulnerability

8.1
CVE-2021-31980

Microsoft Intune Management Extension Remote Code Execution Vulnerability

5.5
CVE-2021-31978

Microsoft Defender Denial of Service Vulnerability

8.6
CVE-2021-31977

Windows Hyper-V Denial of Service Vulnerability

7.5
CVE-2021-31976

Server for NFS Information Disclosure Vulnerability

7.5
CVE-2021-31975

Server for NFS Information Disclosure Vulnerability

7.5
CVE-2021-31974

Server for NFS Denial of Service Vulnerability

7.8
CVE-2021-31973

Windows GPSVC Elevation of Privilege Vulnerability

5.5
CVE-2021-31972

Event Tracing for Windows Information Disclosure Vulnerability

6.8
CVE-2021-31971

Windows HTML Platforms Security Feature Bypass Vulnerability

5.5
CVE-2021-31970

Windows TCP/IP Driver Security Feature Bypass Vulnerability

7.8
CVE-2021-31969

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

7.5
CVE-2021-31968

Windows Remote Desktop Services Denial of Service Vulnerability

7.8
CVE-2021-31967

VP9 Video Extensions Remote Code Execution Vulnerability

7.2
CVE-2021-31966

Microsoft SharePoint Server Remote Code Execution Vulnerability

5.7
CVE-2021-31965

Microsoft SharePoint Server Information Disclosure Vulnerability

7.6
CVE-2021-31964

Microsoft SharePoint Server Spoofing Vulnerability

7.1
CVE-2021-31963

Microsoft SharePoint Server Remote Code Execution Vulnerability

9.4
CVE-2021-31962

Kerberos AppContainer Security Feature Bypass Vulnerability

5.5
CVE-2021-31960

Windows Bind Filter Driver Information Disclosure Vulnerability

6.4
CVE-2021-31959

Scripting Engine Memory Corruption Vulnerability

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started