Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 244/380
7.8
CVE-2021-28321

Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability

7.8
CVE-2021-28320

Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability

7.5
CVE-2021-28319

Windows TCP/IP Driver Denial of Service Vulnerability

5.5
CVE-2021-28318

Windows GDI+ Information Disclosure Vulnerability

5.5
CVE-2021-28317

Microsoft Windows Codecs Library Information Disclosure Vulnerability

4.2
CVE-2021-28316

Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability

7.8
CVE-2021-28315

Windows Media Video Decoder Remote Code Execution Vulnerability

7.8
CVE-2021-28314

Windows Hyper-V Elevation of Privilege Vulnerability

7.8
CVE-2021-28313

Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability

3.3
CVE-2021-28312

Windows NTFS Denial of Service Vulnerability

6.5
CVE-2021-28311

Windows Application Compatibility Cache Denial of Service Vulnerability

7.8
CVE-2021-28310 KEV

Win32k Elevation of Privilege Vulnerability

5.5
CVE-2021-28309

Windows Kernel Information Disclosure Vulnerability

7.8
CVE-2021-27096

NTFS Elevation of Privilege Vulnerability

7.8
CVE-2021-27095

Windows Media Video Decoder Remote Code Execution Vulnerability

4.4
CVE-2021-27094

Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability

5.5
CVE-2021-27093

Windows Kernel Information Disclosure Vulnerability

6.8
CVE-2021-27092

Azure AD Web Sign-in Security Feature Bypass Vulnerability

7.8
CVE-2021-27091

RPC Endpoint Mapper Service Elevation of Privilege Vulnerability

7.8
CVE-2021-27090

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

7.8
CVE-2021-27089

Microsoft Internet Messaging API Remote Code Execution Vulnerability

7.8
CVE-2021-27088

Windows Event Tracing Elevation of Privilege Vulnerability

7.8
CVE-2021-27086

Windows Services and Controller App Elevation of Privilege Vulnerability

5.7
CVE-2021-27079

Windows Media Photo Codec Information Disclosure Vulnerability

7.0
CVE-2021-27072

Win32k Elevation of Privilege Vulnerability

6.5
CVE-2021-27067

Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability

7.8
CVE-2021-27064

Visual Studio Installer Elevation of Privilege Vulnerability

5.5
CVE-2021-26417

Windows Overlay Filter Information Disclosure Vulnerability

7.7
CVE-2021-26416

Windows Hyper-V Denial of Service Vulnerability

7.8
CVE-2021-26415

Windows Installer Elevation of Privilege Vulnerability

6.2
CVE-2021-26413

Windows Installer Spoofing Vulnerability

8.5
CVE-2021-30480

Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary cod

8.8
CVE-2021-21196

Heap buffer overflow in TabStrip in Google Chrome on Windows prior to 89.0.4389.114 allowed a remote attacker to potenti

7.2
CVE-2021-20022 KEV

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload a

9.8
CVE-2021-20021 KEV

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account

7.0
CVE-2021-29221

A local privilege escalation vulnerability was discovered in Erlang/OTP prior to version 23.2.3. By adding files to an e

7.8
CVE-2021-3146

The Dolby Audio X2 (DAX2) API service before 0.8.8.90 on Windows allows local users to gain privileges.

6.5
CVE-2021-20480

IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a spe

7.8
CVE-2021-28927

The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platfor

4.8
CVE-2021-20334

A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary

6.5
CVE-2021-28546

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e

8.1
CVE-2021-28545

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e

7.8
CVE-2021-27271

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.

7.8
CVE-2021-27270

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.

7.8
CVE-2021-27269

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.

7.8
CVE-2021-27268

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.

7.8
CVE-2021-27267

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.1.

3.3
CVE-2021-27266

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomP

3.3
CVE-2021-27265

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomP

3.3
CVE-2021-27264

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomP

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started