Microsoft
91,472 known vulnerabilities
Top Products
An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbol
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects
A security feature bypass vulnerability exists in Windows 10 when third party filters are called during a password updat
An elevation of privilege vulnerability exists when Microsoft Cryptographic Services improperly handles files, aka 'Micr
A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate
A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Se
An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to prop
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka
A denial of service vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an attacker connects to the
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious se
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi
An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, a
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a fi
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a fi
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memor
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this partic
Viscosity 1.8.2 on Windows and macOS allows an unprivileged user to set a subset of OpenVPN parameters, which can be use
Inappropriate implementation in WebRTC in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially e
Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow r
Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote att
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose
When Python was installed on Windows, a python file being served with the MIME type of text/plain could be executed by P
During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and
When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unpriv
In Teradici PCoIP Agent before 19.08.1 and PCoIP Client before 19.08.3, an unquoted service path can cause execution of
An issue was discovered in Suricata 5.0.0. It was possible to bypass/evade any tcp based signature by faking a closed TC
Avira Free Antivirus 15.0.1907.1514 is prone to a local privilege escalation through the execution of kernel code from a
The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code.
NVIDIA GeForce Experience, all versions prior to 3.20.2, contains a vulnerability when GameStream is enabled in which an
Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\n
VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) conta
In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistak
An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3 Agent for Windows that c
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started