Microsoft
91,472 known vulnerabilities
Top Products
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines
A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an
A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
An information disclosure vulnerability exists when the Microsoft Edge Fetch API incorrectly handles a filtered response
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
A security feature bypass vulnerability exists when Windows Subsystem for Linux improperly handles case sensitivity, aka
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window
A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacker sends specially cr
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje
An information disclosure vulnerability exists when the browser scripting engine improperly handle object types, aka "Mi
An information disclosure vulnerability exists in Windows when the Windows bowser.sys kernel-mode driver fails to proper
A denial of service vulnerability exists when OData Library improperly handles web requests, aka "OData Denial of Servic
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packet
An Out-of-Bounds Read Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a
A Missing Impersonation Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow
A Deserialization of Untrusted Data Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5
Adobe Creative Cloud Desktop Application before 4.5.5.342 (installer) has an insecure library loading (dll hijacking) vu
Adobe Flash Player 30.0.0.134 and earlier have a "use of a component with a known vulnerability" vulnerability. Successf
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead t
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead t
Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Successful exploitation could lead to se
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead t
Adobe Photoshop CC 2018 before 19.1.6 and Photoshop CC 2017 before 18.1.6 have a memory corruption vulnerability. Succes
Adobe Photoshop CC 2018 before 19.1.6 and Photoshop CC 2017 before 18.1.6 have a memory corruption vulnerability. Succes
Adobe Acrobat and Reader versions 2018.011.20055 and earlier, 2017.011.30096 and earlier, and 2015.006.30434 and earlier
Adobe Acrobat and Reader versions 2018.011.20055 and earlier, 2017.011.30096 and earlier, and 2015.006.30434 and earlier
A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to manipulate a reverse pr
A Directory Traversal Remote Code Execution vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could al
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows
An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly valida
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka "Microsoft
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles obje
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofi
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started