Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 46/380
8.3
CVE-2026-8523

Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the render

7.5
CVE-2026-8521

Use after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary cod

8.3
CVE-2026-8520

Race in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox esc

8.8
CVE-2026-8519

Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an ou

8.8
CVE-2026-8518

Use after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code ins

5.3
CVE-2026-8516

Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote att

8.3
CVE-2026-8515

Use after free in HID in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage

8.3
CVE-2026-8514

Use after free in Aura in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the render

8.3
CVE-2026-8512

Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to

9.6
CVE-2026-8511

Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox

7.5
CVE-2026-8510

Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromis

8.8
CVE-2026-8509

Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary co

8.1
CVE-2026-42897 KEV

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows

9.6
CVE-2026-41615

Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to

7.8
CVE-2026-0247

Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attack

7.8
CVE-2026-0246

A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally a

5.5
CVE-2026-0245

Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configura

7.8
CVE-2026-44470

The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side

7.8
CVE-2026-34690

After Effects is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution i

7.5
CVE-2026-42899

Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service o

9.9
CVE-2026-42898

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a

7.8
CVE-2026-42896

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

7.4
CVE-2026-42893

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz

6.5
CVE-2026-42891

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized

5.4
CVE-2026-42838

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Ch

9.1
CVE-2026-42833

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a

7.7
CVE-2026-42832

Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.

7.8
CVE-2026-42831

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

6.5
CVE-2026-42830

Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-42825

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

9.9
CVE-2026-42823

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

6.2
CVE-2026-41614

Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.

8.8
CVE-2026-41613

Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

5.5
CVE-2026-41612

Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.

7.8
CVE-2026-41611

Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthoriz

6.3
CVE-2026-41610

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an una

8.8
CVE-2026-41109

Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and

7.4
CVE-2026-41107

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose inf

9.1
CVE-2026-41103

Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unautho

7.1
CVE-2026-41102

Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.

7.1
CVE-2026-41101

Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.

4.4
CVE-2026-41100

Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.

6.7
CVE-2026-41097

Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security

9.8
CVE-2026-41096

Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.

7.8
CVE-2026-41095

Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-41094

Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker t

9.8
CVE-2026-41089

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

7.8
CVE-2026-41088

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an

8.8
CVE-2026-41086

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

4.3
CVE-2026-40421

Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started