Microsoft
91,472 known vulnerabilities
Top Products
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code
An information disclosure vulnerability exists when Windows allows a normal user to access the Wireless LAN profile of a
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Servi
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code int
An denial of service vulnerability exists when Windows NT WEBDAV Minirdr attempts to query a WEBDAV directory, aka "WEBD
An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library driver improperly ha
An Elevation of Privilege vulnerability exists when Cortana retrieves data from user input services without consideratio
An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory, aka "Wi
A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mark of the Web Tagging (M
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs hashing, aka "Window
An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vuln
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet
An information disclosure vulnerability exists when Edge improperly marks files, aka "Microsoft Edge Information Disclos
In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with
A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used fo
The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with ano
On Windows systems, the logger run by the Windows updater deletes the file "update.log" before it runs in order to write
On Windows systems, if non-null-terminated strings are copied into the crash reporter for some specific registry keys, s
An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected,
The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the loc
The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using
An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation th
The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Intern
The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users.
The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. T
The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer w
A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. T
The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a specia
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabl
This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Mainten
The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the upda
When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be ap
Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Window
In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started