Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 72/380
7.1
CVE-2025-62570

Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information loc

7.0
CVE-2025-62569

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

5.3
CVE-2025-62567

Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.

7.3
CVE-2025-62565

Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-62564

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-62563

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-62562

Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-62561

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-62560

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-62559

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-62558

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

8.4
CVE-2025-62557

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-62556

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.0
CVE-2025-62555

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

8.4
CVE-2025-62554

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe

7.8
CVE-2025-62553

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-62552

Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.

8.8
CVE-2025-62550

Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.

8.8
CVE-2025-62549

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to exe

7.8
CVE-2025-62474

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges

6.5
CVE-2025-62473

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose informa

7.8
CVE-2025-62472

Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privi

7.8
CVE-2025-62470

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges

7.0
CVE-2025-62469

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File

5.5
CVE-2025-62468

Out-of-bounds read in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.

7.8
CVE-2025-62467

Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges loca

7.8
CVE-2025-62466

Null pointer dereference in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privilege

6.5
CVE-2025-62465

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

7.8
CVE-2025-62464

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

6.5
CVE-2025-62463

Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.

7.8
CVE-2025-62462

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-62461

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges loca

7.8
CVE-2025-62458

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-62457

Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally

8.8
CVE-2025-62456

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a

7.8
CVE-2025-62455

Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-62454

Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges

7.8
CVE-2025-62221 KEV

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-59517

Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-59516

Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate priv

7.8
CVE-2025-55233

Out-of-bounds read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-54100

Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unau

4.3
CVE-2025-62223

User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker

4.7
CVE-2025-13992

Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote atta

8.0
CVE-2025-20386

In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to

5.5
CVE-2025-13751

Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a loc

7.8
CVE-2025-66476

Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on

8.4
CVE-2025-64298

NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are expose

7.5
CVE-2025-13721

Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via

8.8
CVE-2025-13720

Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer pr

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started