Microsoft
91,472 known vulnerabilities
Top Products
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-b
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineS
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause a denial of
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause memory corru
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bo
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c
Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security
Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform
Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft
Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to m
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network
Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potenti
Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One (C-Werk) before 2
Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.
Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet
After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to m
After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to m
After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to m
A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the fi
Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerabil
Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Desig
Dreamweaver Desktop versions 21.5 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that cou
Premiere Pro versions 25.3, 24.6.5 and earlier are affected by a Use After Free vulnerability that could result in arbit
A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior ver
Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers
Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attack
External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.
Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileg
Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to p
Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code local
SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited
Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to ex
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all
Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized a
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapC
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started