Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 260/380
7.7
CVE-2020-16894

<p>A denial of service vulnerability exists when Windows Network Address Translation (NAT) on a host server fails to pro

7.8
CVE-2020-16892

<p>An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory. An

8.8
CVE-2020-16891

<p>A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input f

7.8
CVE-2020-16890

<p>An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An

5.5
CVE-2020-16889

<p>An information disclosure vulnerability exists when the Windows KernelStream improperly handles objects in memory. An

7.8
CVE-2020-16887

<p>An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles object

5.3
CVE-2020-16886

<p>A security feature bypass vulnerability exists in the PowerShellGet V2 module. An attacker who successfully exploited

7.8
CVE-2020-16885

<p>An elevation of privilege vulnerability exists when the Windows Storage VSP Driver improperly handles file operations

7.1
CVE-2020-16877

<p>An elevation of privilege vulnerability exists when Microsoft Windows improperly handles reparse points. An attacker

7.1
CVE-2020-16876

<p>An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly h

7.5
CVE-2020-16863

<p>A denial of service vulnerability exists in Windows Remote Desktop Service when an attacker connects to the target sy

7.8
CVE-2020-0764

<p>An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations. A

7.1
CVE-2020-3991

VMware Horizon Client for Windows (5.x before 5.5.0) contains a denial-of-service vulnerability due to a file system acc

9.8
CVE-2020-26944

An issue was discovered in Aptean Product Configurator 4.61.0000 on Windows. A Time based SQL injection affects the name

9.8
CVE-2019-19513

The BASSMIDI plugin 2.4.12.1 for Un4seen BASS Audio Library on Windows is prone to an out of bounds write vulnerability.

7.0
CVE-2020-9746

Adobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerabilit

7.8
CVE-2020-17417

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.1.35

7.8
CVE-2020-17416

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.0.35

7.8
CVE-2020-17415

This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PhantomPDF 10.0.0.35

7.8
CVE-2020-17414

This vulnerability allows local attackers to escalate privileges on affected installations of Foxit Reader 10.0.0.35798.

7.8
CVE-2020-17413

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.0.

7.8
CVE-2020-17412

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.0.

3.3
CVE-2020-17411

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomP

7.8
CVE-2020-17410

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.0.

6.2
CVE-2020-7811

Samsung Update 3.0.2.0 ~ 3.0.32.0 has a vulnerability that allows privilege escalation as commands crafted by attacker a

7.8
CVE-2020-26894

LiveCode v9.6.1 on Windows allows local, low-privileged users to gain privileges by creating a malicious "cmd.exe" in th

6.1
CVE-2020-26870

Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily

3.3
CVE-2020-4629

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensi

7.8
CVE-2020-4607

IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security

6.3
CVE-2020-25775

The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary fil

4.3
CVE-2020-25774

A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to trigger an out-of-b

7.8
CVE-2020-25773

A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary c

5.5
CVE-2020-25772

An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to discl

5.5
CVE-2020-25771

An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to discl

5.5
CVE-2020-25770

An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to discl

5.5
CVE-2020-24565

An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to discl

5.5
CVE-2020-24564

An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to discl

7.8
CVE-2020-24563

A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unloa

7.8
CVE-2020-24562

A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any

7.5
CVE-2020-24560

An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family o

7.5
CVE-2020-15604

An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family o

4.3
CVE-2020-4340

IBM Security Secret Server prior to 10.9 could allow an attacker to bypass SSL security due to improper certificate vali

4.3
CVE-2020-4324

IBM Security Secret Server proir to 10.9 could allow a remote attacker to bypass security restrictions, caused by improp

7.8
CVE-2019-15287

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros

7.8
CVE-2019-15285

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros

7.8
CVE-2019-15283

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros

6.5
CVE-2020-6567

Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 al

7.8
CVE-2020-3979

InstallBuilder for Qt Windows (versions prior to 20.7.0) installers look for plugins at a predictable location at initia

6.1
CVE-2020-9745

Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploite

6.1
CVE-2020-9744

Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploite

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started