Microsoft
91,472 known vulnerabilities
Top Products
<p>A denial of service vulnerability exists in Microsoft Outlook software when the software fails to properly handle obj
<p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in m
<p>A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speci
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speci
<p>This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affe
<p>An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Commerce. An unauthenticated attacker who su
<p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder struc
<p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder struc
<p>An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles jun
<p>An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successful
<p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attac
<p>An information disclosure vulnerability exists when the .NET Framework improperly handles objects in memory. An attac
<p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p
<p>An elevation of privilege vulnerability exists when Windows improperly handles COM object creation. An attacker who s
<p>An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles cer
<p>A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files
<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle o
<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle o
<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle o
<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle o
<p>An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles cer
<p>A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target sys
<p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memor
<p>A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory.
<p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully expl
<p>An information disclosure vulnerability exists in Text Services Framework when it fails to properly handle objects in
<p>An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly h
<p>An information disclosure vulnerability exists when the Windows Enterprise App Management Service improperly handles
<p>A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.</p> <p>An at
<p>An elevation of privilege vulnerability exists when Windows improperly handles COM object creation. An attacker who s
<p>A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attac
<p>An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) hand
<p>An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handl
<p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p
<p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles obje
<p>A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, whic
<p>An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files.
<p>An elevation of privilege vulnerability exists in Windows Setup in the way it handles directories.</p> <p>A locally a
<p>An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handl
<p>An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files.
<p>An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.</p> <p>An unauthentic
<p>An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly
<p>An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.</p>
<p>An elevation of privilege vulnerability exists when the Windows Event System improperly handles objects in memory.</p
<p>A denial of service vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement
<p>A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertise
<p>An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) improperly handle objec
<p>An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the targ
<p>An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process cras
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started