Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 48/380
5.5
CVE-2026-35419

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

7.8
CVE-2026-35418

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-35417

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-35416

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an

7.8
CVE-2026-35415

Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges

7.8
CVE-2026-34687

Illustrator versions 29.8.6, 30.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could resu

5.5
CVE-2026-34663

Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to dis

5.5
CVE-2026-34662

Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result

7.8
CVE-2026-34661

Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds write vulnerability that could result in

7.8
CVE-2026-34638

Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by a Use After Free vulnerability that could result in arb

7.8
CVE-2026-34637

Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result

7.8
CVE-2026-34636

Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result

7.8
CVE-2026-34351

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an

6.5
CVE-2026-34350

Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a netw

7.0
CVE-2026-34347

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-34345

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an

7.8
CVE-2026-34344

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an

7.8
CVE-2026-34343

Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate pr

7.0
CVE-2026-34342

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Com

7.0
CVE-2026-34341

Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-34340

Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

5.5
CVE-2026-34339

Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to deny s

7.8
CVE-2026-34338

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-34337

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-34336

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-34334

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an

7.8
CVE-2026-34333

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

8.0
CVE-2026-34332

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.

7.0
CVE-2026-34331

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all

7.8
CVE-2026-34330

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all

8.8
CVE-2026-34329

Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent n

7.8
CVE-2026-33841

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-33840

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-33839

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all

7.8
CVE-2026-33838

Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-33837

Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-33835

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-33834

Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.

8.2
CVE-2026-33833

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Lear

7.7
CVE-2026-33821

Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privi

9.1
CVE-2026-33117

The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path

8.8
CVE-2026-33112

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-33110

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

4.4
CVE-2026-32209

Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature l

7.8
CVE-2026-32204

External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally

5.5
CVE-2026-32185

Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofi

7.3
CVE-2026-32177

Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.

4.3
CVE-2026-32175

A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully

6.7
CVE-2026-32170

Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

7.5
CVE-2026-32161

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Minip

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started