Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 89/380
7.8
CVE-2025-49738

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to

7.0
CVE-2025-49737

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an

8.1
CVE-2025-49735

Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.

7.8
CVE-2025-49733

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-49732

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

3.1
CVE-2025-49731

Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate

7.8
CVE-2025-49730

Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to el

8.8
CVE-2025-49729

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut

7.0
CVE-2025-49727

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-49726

Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-49725

Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.

8.8
CVE-2025-49724

Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a netw

8.8
CVE-2025-49723

Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.

5.7
CVE-2025-49722

Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over

7.8
CVE-2025-49721

Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.

7.5
CVE-2025-49719

Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.

7.5
CVE-2025-49718

Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.

8.5
CVE-2025-49717

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

7.5
CVE-2025-49716

Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.

7.8
CVE-2025-49714

Trust boundary violation in Visual Studio Code - Python extension allows an unauthorized attacker to execute code locall

7.8
CVE-2025-49711

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

6.5
CVE-2025-49706 KEV

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a networ

7.8
CVE-2025-49705

Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

8.8
CVE-2025-49704 KEV

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker t

7.8
CVE-2025-49703

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-49702

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe

8.8
CVE-2025-49701

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

7.8
CVE-2025-49700

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.0
CVE-2025-49699

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-49698

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

8.4
CVE-2025-49697

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

8.4
CVE-2025-49696

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

8.4
CVE-2025-49695

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-49694

Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-49693

Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

8.0
CVE-2025-49691

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network.

7.4
CVE-2025-49690

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem

7.8
CVE-2025-49689

Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally

8.8
CVE-2025-49688

Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a n

8.8
CVE-2025-49687

Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-49686

Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-49685

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

5.5
CVE-2025-49684

Buffer over-read in Storage Port Driver allows an authorized attacker to disclose information locally.

7.8
CVE-2025-49683

Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally.

7.3
CVE-2025-49682

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

6.5
CVE-2025-49681

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor

7.3
CVE-2025-49680

Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized atta

7.8
CVE-2025-49679

Numeric truncation error in Windows Shell allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-49678

Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-49677

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started