Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 77/380
8.2
CVE-2025-59291

External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate

7.8
CVE-2025-59290

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-59289

Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

5.3
CVE-2025-59288

Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofi

9.8
CVE-2025-59287 KEV

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over

7.0
CVE-2025-59285

Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

3.3
CVE-2025-59284

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform sp

7.0
CVE-2025-59282

Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows

7.8
CVE-2025-59281

Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to

3.1
CVE-2025-59280

Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.

7.8
CVE-2025-59278

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevat

7.8
CVE-2025-59277

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevat

7.8
CVE-2025-59275

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevat

7.0
CVE-2025-59261

Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to eleva

5.5
CVE-2025-59260

Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an author

6.5
CVE-2025-59259

Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to d

6.2
CVE-2025-59258

Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker

6.5
CVE-2025-59257

Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to d

7.8
CVE-2025-59255

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-59254

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

5.5
CVE-2025-59253

Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

8.1
CVE-2025-59250

Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a netwo

8.8
CVE-2025-59249

Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

7.5
CVE-2025-59248

Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a networ

6.5
CVE-2025-59244

External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a n

7.8
CVE-2025-59243

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-59242

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate pri

7.8
CVE-2025-59241

Improper link resolution before file access ('link following') in Windows Health and Optimized Experiences Service allow

7.8
CVE-2025-59238

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

8.8
CVE-2025-59237

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.4
CVE-2025-59236

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.1
CVE-2025-59235

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

7.8
CVE-2025-59234

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-59233

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

7.1
CVE-2025-59232

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

7.8
CVE-2025-59231

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

7.8
CVE-2025-59230 KEV

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges

5.5
CVE-2025-59229

Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally.

8.8
CVE-2025-59228

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

7.8
CVE-2025-59227

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-59226

Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-59225

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-59224

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-59223

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-59222

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.0
CVE-2025-59221

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

6.5
CVE-2025-59214

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to p

8.8
CVE-2025-59213

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager

5.5
CVE-2025-59211

Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attack

7.4
CVE-2025-59210

Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started