Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 275/380
7.8
CVE-2020-1201

An elevation of privilege vulnerability exists in the way the Windows Now Playing Session Manager handles objects in mem

7.8
CVE-2020-1199

An elevation of privilege vulnerability exists when the Windows Feedback Hub improperly handles objects in memory, aka '

7.8
CVE-2020-1197

An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash,

7.8
CVE-2020-1196

An elevation of privilege vulnerability exists in the way that the printconfig.dll handles objects in memory, aka 'Windo

5.5
CVE-2020-1194

A denial of service vulnerability exists when Windows Registry improperly handles filesystem operations, aka 'Windows Re

5.4
CVE-2020-1183

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall

8.8
CVE-2020-1181

A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filte

8.8
CVE-2020-1178

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c

5.4
CVE-2020-1177

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall

7.8
CVE-2020-1170

An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To e

7.8
CVE-2020-1163

An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To e

7.8
CVE-2020-1162

An elevation of privilege (user to user) vulnerability exists in Windows Security Health Service when handling certain o

5.5
CVE-2020-1160

An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects

5.4
CVE-2020-1148

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requ

5.5
CVE-2020-1120

A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file o

8.1
CVE-2020-1073

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,

7.8
CVE-2020-0986 KEV

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka '

7.8
CVE-2020-0916

An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objec

7.8
CVE-2020-0915

An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objec

8.8
CVE-2020-13872

Royal TS before 5 has a 0.0.0.0 listener, which makes it easier for attackers to bypass tunnel authentication via a brut

7.8
CVE-2020-11492

An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe p

7.5
CVE-2019-20831

An issue was discovered in the 3D Plugin Beta for Foxit Reader and PhantomPDF before 9.5.0.20733. It has void data misha

9.8
CVE-2019-20822

An issue was discovered in the 3D Plugin Beta for Foxit Reader and PhantomPDF before 9.7.0.29430. It has an out-of-bound

7.8
CVE-2020-7812

Ezhttptrans.ocx ActiveX Control in Kaoni ezHTTPTrans 1.0.0.70 and prior versions contain a vulnerability that could allo

10.0
CVE-2020-12389

The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note

10.0
CVE-2020-12388

The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note

7.8
CVE-2020-12393

The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be c

9.8
CVE-2020-13417

An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CV

3.1
CVE-2020-1195

An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly

7.8
CVE-2020-1192

A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads workspace settings fr

7.8
CVE-2020-1191

An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m

7.8
CVE-2020-1190

An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m

7.8
CVE-2020-1189

An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m

7.8
CVE-2020-1188

An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m

7.8
CVE-2020-1187

An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m

7.8
CVE-2020-1186

An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m

7.8
CVE-2020-1185

An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m

7.8
CVE-2020-1184

An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in m

6.5
CVE-2020-1179

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m

7.8
CVE-2020-1176

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory.

7.8
CVE-2020-1175

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory.

7.8
CVE-2020-1174

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory.

6.8
CVE-2020-1173

A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded

8.8
CVE-2020-1171

A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads configuration files a

7.8
CVE-2020-1166

An elevation of privilege vulnerability exists when Windows improperly handles calls to Clipboard Service. An attacker w

7.8
CVE-2020-1165

An elevation of privilege vulnerability exists when Windows improperly handles calls to Clipboard Service. An attacker w

7.0
CVE-2020-1164

An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacke

7.5
CVE-2020-1161

A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully

7.8
CVE-2020-1158

An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacke

7.8
CVE-2020-1157

An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacke

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started