Microsoft
91,472 known vulnerabilities
Top Products
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier
Adobe Photoshop CC versions 19.1.3 and earlier, 18.1.3 and earlier, and 18.1.2 and earlier have an Out-of-bounds write v
Adobe Flash Player versions 29.0.0.171 and earlier have a Type Confusion vulnerability. Successful exploitation could le
A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH)
uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to tr
AnyDesk before "12.06.2018 - 4.1.3" on Windows 7 SP1 has a DLL preloading vulnerability.
An undisclosed vulnerability in IBM Rational DOORS 9.5.1 through 9.6.1.10 application allows an attacker to gain DOORS a
Untrusted search path vulnerability in the installer of PlayMemories Home for Windows ver.5.5.01 and earlier allows an a
Untrusted search path vulnerability in the installer of Visual C++ Redistributable allows an attacker to gain privileges
Untrusted search path vulnerability in Self-extracting archive files created by IExpress bundled with Microsoft Windows
Untrusted search path vulnerability in the installer of Visual Studio Code allows an attacker to gain privileges via a T
Untrusted search path vulnerability in the installer of Visual Studio Community allows an attacker to gain privileges vi
Untrusted search path vulnerability in the installer of Skype for Windows allows an attacker to gain privileges via a Tr
Untrusted search path vulnerability in Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in
Untrusted search path vulnerability in the installer of Microsoft OneDrive allows an attacker to gain privileges via a T
Untrusted search path vulnerability in Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL i
IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.
ruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be hijacked on Windows OS, when a Symbol is used a
A vulnerability in vpnva-6.sys for 32-bit Windows and vpnva64-6.sys for 64-bit Windows of Cisco AnyConnect Secure Mobili
On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-cli
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka "Media
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje
An elevation of privilege vulnerability exists when Office Web Apps Server 2013 and Office Online Server fail to properl
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka
A remote code execution vulnerability exists when Microsoft Publisher fails to utilize features that lock down the Local
An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly, aka
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
A remote code execution vulnerability exists when HTTP Protocol Stack (Http.sys) improperly handles objects in memory, a
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses speci
A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly ha
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
An elevation of privilege vulnerability exists when Windows Hyper-V instruction emulation fails to properly enforce priv
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started