Microsoft
91,472 known vulnerabilities
Top Products
A remote code execution vulnerability exists when the Windows Font Driver Host improperly handles memory.An attacker who
An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.To exploit th
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windo
An elevation of privilege vulnerability exists when the Windows USO Core Worker improperly handles memory.To exploit thi
An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory,
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in m
An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations, aka
An elevation of privilege vulnerability exists when the Windows Modules Installer improperly handles file operations, ak
An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninit
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker
An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse po
An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handle
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided inpu
This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windo
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the softwar
An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate inpu
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly
XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by settin
RAONWIZ v2018.0.2.50 and eariler versions contains a vulnerability that could allow remote files to be downloaded and ex
When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in
A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26,
A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan hors
Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to
Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow an unauthe
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local at
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a buf
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a den
A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticate
CyMiInstaller322 ActiveX which runs MIPLATFORM downloads files required to run applications. A vulnerability in download
Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into th
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have an out-of-bounds read vulnerability. Successful e
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started