Microsoft
91,472 known vulnerabilities
Top Products
An elevation of privilege vulnerability exists when the Windows IME improperly handles memory.To exploit this vulnerabil
An information disclosure vulnerability exists in the way that affected Microsoft browsers handle cross-origin requests,
An information disclosure vulnerability exists when the Windows Network Driver Interface Specification (NDIS) improperly
An elevation of privilege vulnerability exists when the Windows Wireless Network Manager improperly handles memory.To ex
An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.To exp
A security feature bypass vulnerability exists in Surface Hub when prompting for credentials, aka 'Surface Hub Security
An elevation of privilege vulnerability exists in the way that the Windows Client License Service (ClipSVC) handles obje
An information disclosure vulnerability exists when the Telephony Service improperly discloses the contents of its memor
An elevation of privilege vulnerability exists in Microsoft Office OLicenseHeartbeat task, where an attacker who success
A security feature bypass vulnerability exists in Microsoft Outlook software when it improperly handles the parsing of U
A spoofing vulnerability exists when Office Online Server does not validate origin in cross-origin communications correc
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security Feature Bypass Vulner
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Ser
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious se
An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in
An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka '
An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to proper
An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to proper
An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to proper
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka '
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka '
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka '
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Window
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Window
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka
An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an a
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, whic
A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations,
An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to prop
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
The uv_rwlock_t fallback implementation for Windows XP and Server 2003 in libuv before 1.7.4 does not properly prevent t
Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin before 2.7.0 for WordPress allow remo
When the Windows Logon Integration feature is configured for all versions of BIG-IP Edge Client for Windows, unauthorize
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started