Microsoft
91,472 known vulnerabilities
Top Products
NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows where a local user may obtai
NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 during application installation on Wind
NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows in which an attacker who has
The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13
A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on th
SecureCore Standard Edition Version 2.x allows an attacker to bypass the product 's authentication to log in to a Window
BlueStacks App Player (BlueStacks App Player for Windows 3.0.0 to 4.31.55, BlueStacks App Player for macOS 2.0.0 and lat
PRIMX ZoneCentral before 6.1.2236 on Windows sometimes leaks the plaintext of NTFS files. On non-SSD devices, this is li
A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when the server fails to
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly saniti
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly saniti
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly saniti
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly saniti
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided i
A Cross-site Scripting (XSS) vulnerability exists when Azure App Services on Azure Stack does not properly sanitize user
An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physical media (USB, DVD,
An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially modified rule export fil
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
An information disclosure vulnerability exists when attaching files to Outlook messages, aka "Microsoft Outlook Informat
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structur
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in m
A remote code execution vulnerability exists in Microsoft Project software when it fails to properly handle objects in m
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memo
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, whic
A security feature bypass vulnerability exists when Windows improperly suspends BitLocker Device Encryption, aka "BitLoc
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka "Wi
A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofi
An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Informati
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation
An information disclosure vulnerability exists when Microsoft Outlook fails to respect "Default link type" settings conf
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which coul
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerabili
A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "Windows Security Feat
A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Feder
A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vuln
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started