Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Microsoft

91,472 known vulnerabilities

1,058
CRITICAL
11,903
HIGH
5,674
MEDIUM
354
LOW

Top Products

windows 8173 windows server 2016 5644 windows server 2019 5279 windows server 2012 4134 windows 10 3588 windows server 2022 3387 windows server 2008 3078 windows 10 1809 2579 windows 10 21h2 2553 windows 10 22h2 2550
18,990 CVEs · Page 95/380
7.8
CVE-2025-43555

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability tha

7.8
CVE-2025-43547

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could re

7.8
CVE-2025-43546

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that

7.8
CVE-2025-43545

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could r

7.8
CVE-2025-30330

Illustrator versions 29.3, 28.7.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could resu

5.5
CVE-2025-30329

Animate versions 24.0.8, 23.0.11 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to

7.8
CVE-2025-30328

Animate versions 24.0.8, 23.0.11 and earlier are affected by an out-of-bounds write vulnerability that could result in a

7.8
CVE-2025-30325

Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability tha

7.8
CVE-2025-30324

Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerabi

7.8
CVE-2025-32709 KEV

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privi

7.8
CVE-2025-32707

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

7.8
CVE-2025-32706 KEV

Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges l

7.8
CVE-2025-32705

Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

8.4
CVE-2025-32704

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

5.5
CVE-2025-32703

Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locall

7.8
CVE-2025-32702

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthori

7.8
CVE-2025-32701 KEV

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-30400 KEV

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

7.5
CVE-2025-30397 KEV

Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attac

5.9
CVE-2025-30394

Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to

7.8
CVE-2025-30393

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-30388

Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

9.8
CVE-2025-30387

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker

8.4
CVE-2025-30386

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-30385

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

7.4
CVE-2025-30384

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally

7.8
CVE-2025-30383

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

7.8
CVE-2025-30382

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally

7.8
CVE-2025-30381

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-30379

Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locall

7.0
CVE-2025-30378

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally

8.4
CVE-2025-30377

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-30376

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-30375

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

5.5
CVE-2025-30320

InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that cou

5.5
CVE-2025-30319

InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by a NULL Pointer Dereference vulnerability that cou

7.8
CVE-2025-30318

InDesign Desktop versions ID19.5.2, ID20.2 and earlier are affected by an out-of-bounds write vulnerability that could r

7.8
CVE-2025-30310

Dreamweaver Desktop versions 21.4 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confu

7.8
CVE-2025-29979

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-29978

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-29977

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-29976

Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally

7.8
CVE-2025-29975

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to

5.7
CVE-2025-29974

Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an

7.0
CVE-2025-29973

Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.

7.5
CVE-2025-29971

Out-of-bounds read in Web Threat Defense (WTD.sys) allows an unauthorized attacker to deny service over a network.

7.8
CVE-2025-29970

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

7.5
CVE-2025-29969

Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code

6.5
CVE-2025-29968

Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service

8.8
CVE-2025-29967

Heap-based buffer overflow in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a netw

Frequently Asked Questions

How many CVEs affect Microsoft?

Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Microsoft vulnerabilities?

Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Microsoft vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Microsoft Vulnerabilities

CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.

Get Started