Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 277/380
7.8
CVE-2020-1087

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker

7.8
CVE-2020-1086

An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacke

5.5
CVE-2020-1084

A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain

7.8
CVE-2020-1082

An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The

7.8
CVE-2020-1081

An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while lo

7.8
CVE-2020-1079

An elevation of privilege vulnerability exists when the Windows fails to properly handle objects in memory. An attacker

7.8
CVE-2020-1078

An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain

7.8
CVE-2020-1077

An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacke

5.5
CVE-2020-1076

A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully

5.5
CVE-2020-1075

An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory. An

5.5
CVE-2020-1072

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker

6.8
CVE-2020-1071

An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote Access Common Dialo

7.8
CVE-2020-1070

An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writin

8.8
CVE-2020-1069

A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filte

7.8
CVE-2020-1068

An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations

7.8
CVE-2020-1067

A remote code execution vulnerability exists in the way that Windows handles objects in memory. An attacker who successf

7.8
CVE-2020-1066

An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privileg

4.2
CVE-2020-1065

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory.

7.5
CVE-2020-1064

A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker c

5.4
CVE-2020-1063

A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a speci

7.5
CVE-2020-1062

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerabi

7.5
CVE-2020-1061

A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory. The

7.5
CVE-2020-1060

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerab

4.3
CVE-2020-1059

A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content. An attacker who successfully e

7.5
CVE-2020-1058

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerab

5.4
CVE-2020-1056

An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, whic

5.5
CVE-2020-1055

A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly san

7.0
CVE-2020-1054 KEV

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o

7.8
CVE-2020-1051

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory.

7.8
CVE-2020-1048

An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writin

4.2
CVE-2020-1037

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi

7.5
CVE-2020-1035

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerab

7.8
CVE-2020-1028

A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker

8.8
CVE-2020-1024

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup

8.8
CVE-2020-1023

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup

7.8
CVE-2020-1021

An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The

7.8
CVE-2020-1010

An elevation of privilege vulnerability exists in Windows Block Level Backup Engine Service (wbengine) that allows file

5.5
CVE-2020-0963

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m

7.5
CVE-2020-0909

A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle specially crafted net

9.8
CVE-2020-0901

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje

8.7
CVE-2020-7808

In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js)

9.8
CVE-2020-12651

SecureCRT before 8.7.2 allows remote attackers to execute arbitrary code via an Integer Overflow and a Buffer Overflow b

7.5
CVE-2020-12876

Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulner

7.8
CVE-2020-4468

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused

7.8
CVE-2020-4467

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused

7.8
CVE-2020-4422

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused

4.3
CVE-2020-4365

IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted reques

7.8
CVE-2020-4343

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused

4.3
CVE-2020-4299

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user throug

7.8
CVE-2020-4288

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started