Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 80/380
7.8
CVE-2025-50175

Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-50174

Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-50152

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

9.9
CVE-2025-49708

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.

6.3
CVE-2025-48813

Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.

7.4
CVE-2025-48004

Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

7.0
CVE-2025-47989

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

5.5
CVE-2025-47979

Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose i

7.3
CVE-2025-25004

Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-24990 KEV

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows o

7.8
CVE-2025-24052

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows o

5.3
CVE-2025-27906

IBM Content Navigator 3.0.11, 3.0.15, 3.1.0, and 3.2.0 could expose the directory listing of the application upon using

9.8
CVE-2025-11719

Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caus

6.5
CVE-2025-33096

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user to cause a de

5.7
CVE-2025-2140

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the networ

3.5
CVE-2025-2139

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the networ

3.5
CVE-2025-2138

IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the netw

9.3
CVE-2025-59286

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at

9.3
CVE-2025-59272

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at

8.7
CVE-2025-59271

Redis Enterprise Elevation of Privilege Vulnerability

9.3
CVE-2025-59252

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at

8.8
CVE-2025-59247

Azure PlayFab Elevation of Privilege Vulnerability

9.8
CVE-2025-59246

Azure Entra ID Elevation of Privilege Vulnerability

9.6
CVE-2025-59218

Azure Entra ID Elevation of Privilege Vulnerability

9.3
CVE-2025-55321

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthor

4.3
CVE-2025-36225

IBM Aspera 5.0.0 through 5.0.13.1 could disclose sensitive user information from the system to an authenticated user d

4.9
CVE-2025-36171

IBM Aspera Faspex 5.0.0 through 5.0.13.1 could allow a privileged user to cause a denial of service from improperly vali

5.3
CVE-2023-37401

IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains that should not be truste

8.1
CVE-2025-61787

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command

7.4
CVE-2025-59489

Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loadi

6.7
CVE-2025-23355

NVIDIA Nsight Graphics for Windows contains a vulnerability in an ngfx component, where an attacker could cause a DLL hi

7.8
CVE-2025-34235

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2

9.8
CVE-2025-34196

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application prior to 25.1.141

7.8
CVE-2025-41244 KEV

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with

7.6
CVE-2025-59251

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

7.3
CVE-2025-55322

Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network.

8.8
CVE-2025-10892

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co

8.8
CVE-2025-10891

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co

9.1
CVE-2025-10890

Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-

8.8
CVE-2025-10502

Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit

8.8
CVE-2025-10501

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap

8.8
CVE-2025-10500

Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap co

3.3
CVE-2025-23346

NVIDIA CUDA Toolkit contains a vulnerability in cuobjdump, where an unprivileged user can cause a NULL pointer dereferen

3.3
CVE-2025-23340

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-b

3.3
CVE-2025-23339

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based bu

3.3
CVE-2025-23338

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where a user may cause an out-of-bounds write

3.3
CVE-2025-23308

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buff

4.2
CVE-2025-23275

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a GP

2.5
CVE-2025-23273

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a di

3.3
CVE-2025-23271

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-b

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started