Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 81/380
3.3
CVE-2025-23248

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-b

6.7
CVE-2025-54081

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineS

9.8
CVE-2025-34195

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330

7.8
CVE-2025-34194

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to

9.8
CVE-2025-34193

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to

7.0
CVE-2025-59220

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service

7.0
CVE-2025-59216

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon

7.0
CVE-2025-59215

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

4.4
CVE-2025-23336

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause a denial of

7.5
CVE-2025-23329

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause memory corru

7.5
CVE-2025-23328

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bo

9.8
CVE-2025-23316

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c

4.0
CVE-2025-49728

Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security

4.7
CVE-2025-47967

Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform

7.8
CVE-2025-54262

Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft

5.5
CVE-2025-54237

Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to m

8.8
CVE-2025-55319

Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network

8.8
CVE-2025-10200

Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potenti

4.6
CVE-2025-10227

Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2

9.8
CVE-2025-10226

Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.

5.5
CVE-2025-10221

Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet

5.5
CVE-2025-54241

After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to m

5.5
CVE-2025-54240

After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to m

5.5
CVE-2025-54239

After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to m

9.8
CVE-2025-43491

A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the fi

7.8
CVE-2025-54257

Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerabil

4.0
CVE-2025-54255

Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Desig

8.6
CVE-2025-54256

Dreamweaver Desktop versions 21.5 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that cou

7.8
CVE-2025-54242

Premiere Pro versions 25.3, 24.6.5 and earlier are affected by a Use After Free vulnerability that could result in arbit

7.8
CVE-2025-10199

A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior ver

7.8
CVE-2025-10198

Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers

7.8
CVE-2025-55317

Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attack

7.8
CVE-2025-55316

External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-55245

Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileg

7.5
CVE-2025-55243

Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to p

7.3
CVE-2025-55236

Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code local

8.8
CVE-2025-55234

SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited

9.8
CVE-2025-55232

Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to ex

7.8
CVE-2025-55228

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all

8.8
CVE-2025-55227

Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized a

6.7
CVE-2025-55226

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an

6.5
CVE-2025-55225

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor

7.8
CVE-2025-55224

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all

7.0
CVE-2025-55223

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an

7.5
CVE-2025-54919

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all

8.8
CVE-2025-54918

Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

4.3
CVE-2025-54917

Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a

7.8
CVE-2025-54916

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

6.7
CVE-2025-54915

Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized

7.8
CVE-2025-54913

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapC

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started