Microsoft
91,472 known vulnerabilities
Top Products
The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly re
The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, th
The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underl
During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-o
When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and thi
The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malfo
There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF,
An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an in
When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotatio
The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper
When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlyi
After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form e
When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object
The application re-enters the document structure via field processing and deletes the current page, and then continues u
When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature
When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to valida
After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verifica
During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document stat
The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete
The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related
When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old fie
The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege use
After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the
When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the under
When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in t
Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the
The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the
The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for crit
Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this is
Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An una
Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over
Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to pe
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based)
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execu
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based)
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized a
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized a
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a netw
Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker t
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started