Microsoft
91,472 known vulnerabilities
Top Products
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, a
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
VMware Horizon Connection Server (7.x before 7.8, 7.5.x before 7.5.2, 6.x before 6.2.8) contains an information disclosu
VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately
VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle paths appropriately. Succ
When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Win
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images
A remote code execution vulnerability exists when the Visual Studio C++ Redistributable Installer improperly validates i
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks, aka '
A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially c
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
A remote code execution vulnerability exists in the way that the ActiveX Data objects (ADO) handles objects in memory, a
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, ak
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft E
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided i
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restri
An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.To explo
An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary
A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory, aka 'Comctl32 Remot
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet
A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins,
A security feature bypass vulnerability exists when Internet Explorer fails to validate the correct Security Zone of req
An information disclosure vulnerability exists when the Windows Print Spooler does not properly handle objects in memory
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attack
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles obj
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in M
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP respon
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Win
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Win
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP respon
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP respon
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka '
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started