Microsoft
91,472 known vulnerabilities
Top Products
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje
An elevation of privilege vulnerability exists when Windows improperly handles Secure Socket Shell remote commands, aka
An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to proper
An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to proper
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific mal
An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in
An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in
An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to proper
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations,
An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, a
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory,
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objec
An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in
An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in
An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in
An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in
An elevation of privilege vulnerability exists in the way that the dssvc.dll handles file creation allowing for a file o
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media
An elevation of privilege vulnerability exists in the way that the tapisrv.dll handles objects in memory, aka 'Windows E
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious se
An elevation of privilege vulnerability exists when the Windows Malicious Software Removal Tool (MSRT) improperly handle
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlin
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file
An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'W
An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry Service improperly hand
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory,
An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Informati
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation
A remote code execution vulnerability exists when the Windows Imaging Library improperly handles memory.To exploit this
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started