Microsoft
91,472 known vulnerabilities
Top Products
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successful exploitation could
Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, w
An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locall
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enfor
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a speci
An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length o
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memo
A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'W
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objec
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, a
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory,
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory,
A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofi
An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memo
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memo
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash,
An elevation of privilege vulnerability exists when umpo.dll of the Power Service, improperly handles a Registry Restore
An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka '
A security feature bypass vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to success
An information disclosure vulnerability exists when Windows Update Client fails to properly handle objects in memory, ak
An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle p
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started