Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 25/380
7.8
CVE-2026-57260

The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly re

6.5
CVE-2026-57259

The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, th

6.1
CVE-2026-57258

The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underl

6.1
CVE-2026-57257

During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-o

7.8
CVE-2026-57256

When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and thi

6.1
CVE-2026-57255

The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malfo

7.8
CVE-2026-57254

There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF,

6.1
CVE-2026-57253

An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an in

7.8
CVE-2026-57252

When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotatio

7.8
CVE-2026-57251

The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper

7.8
CVE-2026-57250

When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlyi

7.8
CVE-2026-57249

After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form e

7.8
CVE-2026-57248

When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object

7.8
CVE-2026-57247

The application re-enters the document structure via field processing and deletes the current page, and then continues u

7.8
CVE-2026-57246

When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature

7.8
CVE-2026-57245

When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to valida

7.8
CVE-2026-57244

After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verifica

6.1
CVE-2026-57243

During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document stat

7.8
CVE-2026-57242

The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete

6.1
CVE-2026-57241

The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related

7.8
CVE-2026-57240

When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old fie

8.2
CVE-2026-57239

The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege use

7.8
CVE-2026-57238

After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the

7.8
CVE-2026-57237

When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the under

7.8
CVE-2026-13129

When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in t

7.8
CVE-2026-13128

Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the

7.8
CVE-2026-13127

The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the

7.8
CVE-2026-13126

The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a

8.1
CVE-2026-13020

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on

9.8
CVE-2026-13019

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for crit

9.8
CVE-2026-9182

Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this is

9.8
CVE-2026-9181

Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An una

6.5
CVE-2026-58523

Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over

4.3
CVE-2026-58597

Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to pe

5.4
CVE-2026-58524

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based)

6.8
CVE-2026-58522

Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

6.2
CVE-2026-58300

Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

7.5
CVE-2026-58299

Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execu

7.2
CVE-2026-58298

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based)

7.1
CVE-2026-58297

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized a

7.1
CVE-2026-58296

Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized a

8.3
CVE-2026-58295

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized

7.5
CVE-2026-58294

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

8.1
CVE-2026-58293

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code

7.5
CVE-2026-58292

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a netw

6.1
CVE-2026-58291

Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker t

7.5
CVE-2026-58290

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized

9.0
CVE-2026-58289

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized

8.3
CVE-2026-58288

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

8.3
CVE-2026-58287

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started