Microsoft
91,472 known vulnerabilities
Top Products
XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have un
Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive
In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Phanto
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Phanto
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Phanto
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF. Us
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User i
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User i
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User i
Double free in Intel(R) SGX SDK for Linux before version 2.2 and Intel(R) SGX SDK for Windows before version 2.1 may all
Buffer leakage in igdkm64.sys in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059),
Multiple pointer dereferences in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059
Untrusted search path vulnerability in The installer of Microsoft Teams allows an attacker to gain privileges via a Troj
Untrusted search path vulnerability in Windows 7 allows an attacker to gain privileges via a Trojan horse DLL in an unsp
azure-umqtt-c (available through GitHub prior to 2017 October 6) allows remote attackers to cause a denial of service vi
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer ov
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer ov
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer ov
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer ov
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overfl
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is affected by buffer overfl
Go through 1.12 on Windows misuses certain LoadLibrary functionality, leading to DLL injection.
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided i
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided i
An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information, aka 'Azure IoT
An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, al
A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker w
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles obj
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles obj
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles obj
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles obj
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles obj
A spoofing vulnerability exists in Microsoft SharePoint when the application does not properly parse HTTP content, aka '
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.To explo
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations, aka 'Windows
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in M
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framewor
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka '
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started