Microsoft
91,472 known vulnerabilities
Top Products
An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerabili
An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerabili
An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerabili
An elevation of privilege vulnerability exists in the way that the wlansvc.dll handles objects in memory, aka 'Windows W
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-p
A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests, a
An elevation of privilege vulnerability exists in Microsoft Windows where a certain DLL, with Local Service privilege, i
An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files,
An elevation of privilege vulnerability exists when the Visual Studio updater service improperly handles file permission
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided i
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerab
An elevation of privilege vulnerability exists in Microsoft Windows where certain folders, with local service privilege,
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka '
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Erro
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation
A security feature bypass vulnerability exists when Active Directory Federation Services (ADFS) improperly updates its l
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a
An elevation of privilege vulnerability exists in Azure Automation "RunAs account" runbooks for users with contributor r
A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 E
A denial of service vulnerability exists when SymCrypt improperly handles a specially crafted digital signature.An attac
A denial of service vulnerability exists in Windows DNS Server when it fails to properly handle DNS queries, aka 'Window
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted pac
The Windows versions of Snapview Mikogo, versions before 5.10.2 are affected by insecure implementations which allow loc
IBM Jazz for Service Management 1.1.3 and 1.1.3.2 stores sensitive information in URL parameters. This may lead to infor
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v1.0 for Windows could allow an authe
The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for
A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php wi
A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(10
An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validate
A vulnerability in Cisco Advanced Malware Protection (AMP) for Endpoints for Windows could allow an authenticated, local
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) tha
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an authenticated user to execute a fu
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer ov
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cr
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 is vulnerable to a denial of serv
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow malicious user w
Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentiall
Integer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially ex
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started