Microsoft
91,472 known vulnerabilities
Top Products
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka '
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScrip
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messa
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations,
An elevation of privilege vulnerability exists when ActiveX Installer service may allow access to files without proper a
An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locat
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 E
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations,
An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka '
A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShel
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memo
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles IPv6 flowlabel filled in
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerabi
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly vali
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly vali
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.7.0-00 allows an unauthenticated remote user to trigger a
A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read inter
NVIDIA Windows GPU Display Driver, R390 driver version, contains a vulnerability in NVIDIA Control Panel in which it inc
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) in whi
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handle
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handle
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handle
An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthentica
A Cross Site Scripting (XSS) issue exists in AVG AntiVirus (Internet Security Edition) 19.3.3084 build 19.3.4241.440 in
A Cross Site Scripting (XSS) issue exists in Avast AntiVirus (Free, Internet Security, and Premiere Edition) 19.3.2369 b
Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL execu
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing pas
Trend Micro Apex One could be exploited by an attacker utilizing a command injection vulnerability to extract files from
Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vul
A File Masquerade vulnerability in McAfee Total Protection (MTP) version 16.0.R21 and earlier in Windows client allowed
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0
browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windo
A DLL side loading vulnerability in the Windows Service in TeamViewer versions up to 11.0.133222 (fixed in 11.0.214397),
Adobe Acrobat and Reader versions 2019.010.20100 and earlier; 2019.010.20099 and earlier versions; 2017.011.30140 and ea
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
Creative Cloud Desktop Application version 4.6.1 and earlier versions have Security Bypass vulnerability. Successful exp
When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow st
IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 is vulnerable to a buffer overflow, caused by improper bounds c
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started