Microsoft
91,472 known vulnerabilities
Top Products
Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to dis
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to dis
Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally
Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.
Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally.
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacke
Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security
Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Managemen
Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.
Null pointer dereference in Windows Drivers allows an unauthorized attacker to elevate privileges locally.
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to dis
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to exec
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose infor
Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to dis
Use of uninitialized resource in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose info
Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elev
Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.
Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an a
External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privil
Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a se
conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR
A vulnerability was found in MTSoftware C-Lodop 6.6.1.1 on Windows. It has been rated as critical. This issue affects so
A vulnerability, which was classified as critical, has been found in Discord 1.0.9188 on Windows. Affected by this issue
Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
Improper access control in Azure allows an unauthorized attacker to disclose information over a network.
Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing
Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges ov
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized
IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial of service as the server may crash under
A vulnerability was found in xiaowei1118 java_server up to 11a5bac8f4ba1c17e4bc1b27cad6d24868500e3a on Windows and class
A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that
Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute c
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.
Frequently Asked Questions
How many CVEs affect Microsoft?
Microsoft has 91,472 CVE records in our database, including 2628 critical and 63090 high severity vulnerabilities. 351 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Microsoft vulnerabilities?
Microsoft has 2628 critical severity (CVSS 9.0+) and 63090 high severity (CVSS 7.0-8.9) vulnerabilities. 351 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Microsoft vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Microsoft products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Microsoft Vulnerabilities
CyberStrike scans your infrastructure for Microsoft vulnerabilities and provides real-time remediation guidance.
Get Started