Microsoft
91,472 known vulnerabilities
Top Products
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a networ
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office S
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevat
Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent networ
Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disc
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.
Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph
Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perfo
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a net
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to el
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authori
Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to exec
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate pri
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthoriz
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose informati
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started