Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 242/380
5.4
CVE-2021-20448

IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J

6.2
CVE-2021-20536

IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files tha

7.8
CVE-2021-20532

IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full

8.4
CVE-2020-7861

AnySupport (Remote support solution) before 2019.3.21.0 allows directory traversing because of swprintf function to copy

6.8
CVE-2020-7858

There is a directory traversing vulnerability in the download page url of AquaNPlayer 2.0.0.92. The IP of the download p

6.1
CVE-2021-1079

NVIDIA GeForce Experience, all versions prior to 3.22, contains a vulnerability in GameStream plugins where log files ar

4.9
CVE-2021-20023 KEV

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an

6.5
CVE-2021-21070

Adobe Robohelp version 2020.0.3 (and earlier) is affected by an uncontrolled search path element vulnerability that coul

7.8
CVE-2020-7851

Innorix Web-Based File Transfer Solution versuibs prior to and including 9.2.18.385 contains a vulnerability that could

6.5
CVE-2020-9681

Adobe Genuine Service version 6.6 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An aut

7.8
CVE-2020-9668

Adobe Genuine Service version 6.6 (and earlier) is affected by an Improper Access control vulnerability when handling sy

6.5
CVE-2020-9667

Adobe Genuine Service version 6.6 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An aut

6.1
CVE-2021-26582

A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0

7.8
CVE-2021-28549

Adobe Photoshop versions 21.2.6 (and earlier) and 22.3 (and earlier) are affected by a Buffer Overflow vulnerability whe

7.8
CVE-2021-28548

Adobe Photoshop versions 21.2.6 (and earlier) and 22.3 (and earlier) are affected by a Buffer Overflow vulnerability whe

5.5
CVE-2021-21096

Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Improper Authorization vulnerabil

7.8
CVE-2021-21095

Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Out-of-bounds write vulnerability

7.8
CVE-2021-21094

Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Out-of-bounds write vulnerability

7.8
CVE-2021-21093

Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by a memory corruption vulnerability wh

7.8
CVE-2021-21092

Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by a memory corruption vulnerability wh

3.3
CVE-2021-21091

Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Out-of-bounds read vulnerability

8.8
CVE-2021-28826

The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Bridge -

8.8
CVE-2021-28825

The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Co

9.0
CVE-2021-28483

Microsoft Exchange Server Remote Code Execution Vulnerability

8.8
CVE-2021-28482

Microsoft Exchange Server Remote Code Execution Vulnerability

9.8
CVE-2021-28481

Microsoft Exchange Server Remote Code Execution Vulnerability

9.8
CVE-2021-28480

Microsoft Exchange Server Remote Code Execution Vulnerability

7.0
CVE-2021-28477

Visual Studio Code Remote Code Execution Vulnerability

7.8
CVE-2021-28475

Visual Studio Code Remote Code Execution Vulnerability

7.8
CVE-2021-28473

Visual Studio Code Remote Code Execution Vulnerability

7.8
CVE-2021-28472

Visual Studio Code Maven for Java Extension Remote Code Execution Vulnerability

7.8
CVE-2021-28471

Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability

7.8
CVE-2021-28470

Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability

7.8
CVE-2021-28469

Visual Studio Code Remote Code Execution Vulnerability

7.8
CVE-2021-28468

Raw Image Extension Remote Code Execution Vulnerability

7.8
CVE-2021-28466

Raw Image Extension Remote Code Execution Vulnerability

7.8
CVE-2021-28464

VP9 Video Extensions Remote Code Execution Vulnerability

8.1
CVE-2021-28460

Azure Sphere Unsigned Code Execution Vulnerability

6.1
CVE-2021-28459

Azure DevOps Server Spoofing Vulnerability

7.8
CVE-2021-28458

Azure ms-rest-nodeauth Library Elevation of Privilege Vulnerability

7.8
CVE-2021-28457

Visual Studio Code Remote Code Execution Vulnerability

5.5
CVE-2021-28456

Microsoft Excel Information Disclosure Vulnerability

7.8
CVE-2021-28454

Microsoft Excel Remote Code Execution Vulnerability

7.8
CVE-2021-28453

Microsoft Word Remote Code Execution Vulnerability

7.1
CVE-2021-28452

Microsoft Outlook Memory Corruption Vulnerability

7.8
CVE-2021-28451

Microsoft Excel Remote Code Execution Vulnerability

5.0
CVE-2021-28450

Microsoft SharePoint Denial of Service Vulnerability

7.8
CVE-2021-28449

Microsoft Office Remote Code Execution Vulnerability

7.8
CVE-2021-28448

Visual Studio Code Kubernetes Tools Remote Code Execution Vulnerability

4.4
CVE-2021-28447

Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started