Microsoft
91,472 known vulnerabilities
Top Products
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacke
A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The
An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while lo
An elevation of privilege vulnerability exists when the Windows fails to properly handle objects in memory. An attacker
An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacke
A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully
An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory. An
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker
An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote Access Common Dialo
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writin
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filte
An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations
A remote code execution vulnerability exists in the way that Windows handles objects in memory. An attacker who successf
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privileg
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory.
A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker c
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a speci
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerabi
A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory. The
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerab
A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content. An attacker who successfully e
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerab
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, whic
A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly san
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory.
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writin
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerab
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The
An elevation of privilege vulnerability exists in Windows Block Level Backup Engine Service (wbengine) that allows file
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle specially crafted net
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje
In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js)
SecureCRT before 8.7.2 allows remote attackers to execute arbitrary code via an Integer Overflow and a Buffer Overflow b
Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulner
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused
IBM WebSphere Application Server 8.5 is vulnerable to server-side request forgery. By sending a specially crafted reques
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user throug
IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started