Microsoft
91,472 known vulnerabilities
Top Products
An elevation of privilege vulnerability exists in the way the Windows Now Playing Session Manager handles objects in mem
An elevation of privilege vulnerability exists when the Windows Feedback Hub improperly handles objects in memory, aka '
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash,
An elevation of privilege vulnerability exists in the way that the printconfig.dll handles objects in memory, aka 'Windo
A denial of service vulnerability exists when Windows Registry improperly handles filesystem operations, aka 'Windows Re
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filte
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To e
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To e
An elevation of privilege (user to user) vulnerability exists in Windows Security Health Service when handling certain o
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requ
A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file o
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka '
An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objec
An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objec
Royal TS before 5 has a 0.0.0.0 listener, which makes it easier for attackers to bypass tunnel authentication via a brut
An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe p
An issue was discovered in the 3D Plugin Beta for Foxit Reader and PhantomPDF before 9.5.0.20733. It has void data misha
An issue was discovered in the 3D Plugin Beta for Foxit Reader and PhantomPDF before 9.7.0.29430. It has an out-of-bound
Ezhttptrans.ocx ActiveX Control in Kaoni ezHTTPTrans 1.0.0.70 and prior versions contain a vulnerability that could allo
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be c
An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CV
An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly
A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads workspace settings fr
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory.
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory.
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory.
A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded
A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads configuration files a
An elevation of privilege vulnerability exists when Windows improperly handles calls to Clipboard Service. An attacker w
An elevation of privilege vulnerability exists when Windows improperly handles calls to Clipboard Service. An attacker w
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacke
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacke
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacke
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started