Microsoft
91,472 known vulnerabilities
Top Products
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
An elevation of privilege vulnerability exists in Remote Desktop App for Mac in the way it allows an attacker to load un
An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in
An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka '
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje
An elevation of privilege vulnerability exists when the Visual Studio Extension Installer Service improperly handles fil
An elevation of privilege vulnerability exists when Microsoft Visual Studio updater service improperly handles file perm
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory,
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation
An elevation of privilege vulnerability exists when Windows Defender antimalware platform improperly handles hard links,
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation
A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Micro
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed
An insecure temporary file vulnerability in Palo Alto Networks Traps allows a local authenticated Windows user to escala
Improper input validation vulnerability in Secdo allows an authenticated local user with 'create folders or append data'
Incorrect Default Permissions on C:\Programdata\Secdo\Logs folder in Secdo allows local authenticated users to overwrite
Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create fol
STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged
In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file del
The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoint
The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under cert
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Servi
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Servi
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Servi
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Servi
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Servi
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Servi
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Servi
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Servi
An issue was discovered in Avast Antivirus before 20. An Arbitrary Memory Address Overwrite vulnerability in the aswAvLo
Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed
Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds
Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corrupti
Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corrupti
Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corrupti
Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corrupti
Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corrupti
Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corrupti
Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corrupti
Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a heap corruption
Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started