Microsoft
91,472 known vulnerabilities
Top Products
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0
An Information Disclosure vulnerability exists in HP SiteScope 11.2 and 11.3 on Windows, Linux and Solaris, HP Asset Man
IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific
A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to
Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea
Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea
Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea
Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea
Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lea
IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS client connecting to a Queue Manager could cause a SIGSEGV denial of service
IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS could allow a remote attacker with intimate knowledge of the server to cause
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
Adobe Acrobat and Reader versions 2019.010.20064 and earlier, 2019.010.20064 and earlier, 2017.011.30110 and earlier ver
Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.
A vulnerability in the Cisco Webex Teams client for Windows could allow an authenticated, remote attacker to cause the c
A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email mess
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlin
An elevation of privilege vulnerability exists in Visual Studio Code when it exposes a debug listener to users of a loca
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual
A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual
An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Server, aka 'Microsoft Dynamics 365 Elevation o
Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate pri
tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consume
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products whic
The repair operation of VMware Tools for Windows 10.x.y has a race condition which may allow for privilege escalation in
A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow authenticated RDP-conne
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a speci
A security feature bypass vulnerability exists in Microsoft OneDrive App for Android.This could allow an attacker to byp
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle obj
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje
A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications correctly, ak
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.N
An elevation of privilege vulnerability exists when Microsoft Windows implements predictable memory section names, aka '
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet
An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to prop
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this
An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles credential information,
An elevation of privilege vulnerability exists in the way that the Windows Subsystem for Linux handles files, aka 'Windo
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started