Microsoft
91,472 known vulnerabilities
Top Products
<p>A denial of service vulnerability exists when Windows Network Address Translation (NAT) on a host server fails to pro
<p>An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory. An
<p>A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input f
<p>An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An
<p>An information disclosure vulnerability exists when the Windows KernelStream improperly handles objects in memory. An
<p>An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles object
<p>A security feature bypass vulnerability exists in the PowerShellGet V2 module. An attacker who successfully exploited
<p>An elevation of privilege vulnerability exists when the Windows Storage VSP Driver improperly handles file operations
<p>An elevation of privilege vulnerability exists when Microsoft Windows improperly handles reparse points. An attacker
<p>An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly h
<p>A denial of service vulnerability exists in Windows Remote Desktop Service when an attacker connects to the target sy
<p>An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations. A
VMware Horizon Client for Windows (5.x before 5.5.0) contains a denial-of-service vulnerability due to a file system acc
An issue was discovered in Aptean Product Configurator 4.61.0000 on Windows. A Time based SQL injection affects the name
The BASSMIDI plugin 2.4.12.1 for Un4seen BASS Audio Library on Windows is prone to an out of bounds write vulnerability.
Adobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerabilit
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.1.35
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.0.0.35
This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PhantomPDF 10.0.0.35
This vulnerability allows local attackers to escalate privileges on affected installations of Foxit Reader 10.0.0.35798.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.0.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.0.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomP
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 10.0.
Samsung Update 3.0.2.0 ~ 3.0.32.0 has a vulnerability that allows privilege escalation as commands crafted by attacker a
LiveCode v9.6.1 on Windows allows local, low-privileged users to gain privileges by creating a malicious "cmd.exe" in th
Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensi
IBM Security Secret Server (IBM Security Verify Privilege Vault Remote 1.2 ) could allow a local user to bypass security
The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary fil
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to trigger an out-of-b
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary c
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to discl
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to discl
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to discl
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to discl
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to discl
A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unloa
A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family o
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family o
IBM Security Secret Server prior to 10.9 could allow an attacker to bypass SSL security due to improper certificate vali
IBM Security Secret Server proir to 10.9 could allow a remote attacker to bypass security restrictions, caused by improp
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros
Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 al
InstallBuilder for Qt Windows (versions prior to 20.7.0) installers look for plugins at a predictable location at initia
Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploite
Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploite
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started