Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 348/380
7.8
CVE-2018-1039

A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, a

4.3
CVE-2018-1025

An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory, aka

7.5
CVE-2018-1022

A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow

4.3
CVE-2018-1021

An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft

7.6
CVE-2018-0961

A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate vSMB packe

7.6
CVE-2018-0959

A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from

5.3
CVE-2018-0958

A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Win

7.5
CVE-2018-0955

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet

7.5
CVE-2018-0954

A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow

7.5
CVE-2018-0953

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft

7.5
CVE-2018-0951

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft

7.5
CVE-2018-0946

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft

7.5
CVE-2018-0945

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft

7.5
CVE-2018-0943

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi

5.3
CVE-2018-0854

A security feature bypass vulnerability exists in Windows Scripting Host which could allow an attacker to bypass Device

8.8
CVE-2018-0824 KEV

A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized

7.5
CVE-2018-0765

A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Co

8.6
CVE-2018-8115

A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to prope

7.8
CVE-2017-14010

In SpiderControl MicroBrowser Windows XP, Vista 7, 8 and 10, Versions 1.6.30.144 and prior, an uncontrolled search path

7.5
CVE-2018-8118

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet

5.3
CVE-2018-1035

A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Win

7.2
CVE-2018-5511

On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Manageme

6.8
CVE-2018-8117

A security feature bypass vulnerability exists in the Microsoft Wireless Keyboard 850 which could allow an attacker to r

5.5
CVE-2018-8116

A denial of service vulnerability exists in the way that Windows handles objects in memory, aka "Microsoft Graphics Comp

4.3
CVE-2018-1037

An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized

5.4
CVE-2018-1034

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c

5.4
CVE-2018-1032

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c

8.8
CVE-2018-1030

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle obj

7.8
CVE-2018-1029

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje

8.8
CVE-2018-1028

A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted emb

7.8
CVE-2018-1027

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje

8.8
CVE-2018-1026

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle obj

7.5
CVE-2018-1023

A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka "Microsoft

7.5
CVE-2018-1020

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet

7.5
CVE-2018-1019

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi

7.5
CVE-2018-1018

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet

8.8
CVE-2018-1016

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded

8.8
CVE-2018-1015

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded

5.4
CVE-2018-1014

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c

8.8
CVE-2018-1013

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded

8.8
CVE-2018-1012

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded

7.8
CVE-2018-1011

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle obje

8.8
CVE-2018-1010

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded

7.8
CVE-2018-1009

An elevation of privilege vulnerability exists when Windows improperly handles objects in memory and incorrectly maps ke

7.0
CVE-2018-1008

An elevation of privilege vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to pr

5.3
CVE-2018-1007

An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, ak

5.4
CVE-2018-1005

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c

8.8
CVE-2018-1004

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows

7.8
CVE-2018-1003

A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an

7.5
CVE-2018-1001

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started