Microsoft
91,472 known vulnerabilities
Top Products
Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the render
Use after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary cod
Race in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox esc
Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an ou
Use after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code ins
Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote att
Use after free in HID in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage
Use after free in Aura in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the render
Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to
Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox
Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromis
Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary co
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows
Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to
Multiple authorization bypass vulnerabilities in the Endpoint DLP component of Prisma Access Agent® allow a local attack
A vulnerability with a privilege management mechanism in the Palo Alto Networks Prisma Access Agent® enables a locally a
Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configura
The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side
After Effects is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution i
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service o
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a
Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Ch
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthoriz
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an una
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose inf
Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unautho
Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.
Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.
Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security
Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.
Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.
Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker t
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started