Microsoft
Microsoft Corporation is an American multinational technology company headquartered in Redmond, Washington. The company became influential in the rise of personal computers through software like Windows and has since expanded into areas such as Internet services, cloud computing, artificial intelligence, video gaming, and more. A Big Tech company, Microsoft is the largest software company by revenue, one of the most valuable public companies, and one of the most valuable brands globally.
Products
2,492- 5,318 CVEs
- 5,109 CVEs
- 4,947 CVEs
- 4,890 CVEs
- 4,279 CVEs
- 3,986 CVEs
- 3,876 CVEs
- 3,572 CVEs
- 2,653 CVEs
- 2,445 CVEs
- 2,374 CVEs
- 2,222 CVEs
- 2,077 CVEs
- 1,923 CVEs
- 1,915 CVEs
- 1,731 CVEs
- 1,587 CVEs
- 1,387 CVEs
- 1,302 CVEs
- 1,186 CVEs
- 951 CVEs
- 926 CVEs
- 802 CVEs
- 747 CVEs
- 672 CVEs
- 654 CVEs
- 531 CVEs
- 522 CVEs
- 420 CVEs
- 412 CVEs
- View all 2,492 products →
Recent CVEs
15,658| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-0796 | Cri | 0.94 | 10.0 | 1.00 | KEV | Mar 12, 2020 | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'. | |
| CVE-2025-53770 | Cri | 0.93 | 9.8 | 1.00 | KEV | Jul 20, 2025 | Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update… | |
| CVE-2023-29357 | Cri | 0.93 | 9.8 | 1.00 | KEV | Jun 14, 2023 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | |
| CVE-2021-38647 | Cri | 0.93 | 9.8 | 1.00 | KEV | Sep 15, 2021 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | |
| CVE-2019-0708 | Cri | 0.93 | 9.8 | 1.00 | KEV | May 16, 2019 | A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution… | |
| CVE-2019-0604 | Cri | 0.93 | 9.8 | 1.00 | KEV | Mar 5, 2019 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594. | |
| CVE-2021-34473 | Cri | 0.88 | 9.1 | 1.00 | KEV | Jul 14, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2021-26855 | Cri | 0.88 | 9.1 | 1.00 | KEV | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2025-59287 | Cri | 0.87 | 9.8 | 1.00 | KEV | Oct 14, 2025 | Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | |
| CVE-2021-34523 | Cri | 0.87 | 9.0 | 1.00 | KEV | Jul 14, 2021 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| CVE-2021-31166 | Cri | 0.87 | 9.8 | 1.00 | KEV | May 11, 2021 | HTTP Protocol Stack Remote Code Execution Vulnerability | |
| CVE-2020-0646 | Cri | 0.87 | 9.8 | 0.99 | KEV | Jan 14, 2020 | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'. | |
| CVE-2015-1635 | Cri | 0.87 | 9.8 | 1.00 | KEV | Apr 14, 2015 | HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability." | |
| CVE-2008-4250 | Cri | 0.87 | 9.8 | 0.99 | KEV | Oct 23, 2008 | The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as… | |
| CVE-2025-49704 | Hig | 0.86 | 8.8 | 1.00 | KEV | Jul 8, 2025 | Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| CVE-2022-41040 | Hig | 0.86 | 8.8 | 1.00 | KEV | Oct 3, 2022 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| CVE-2021-40444 | Hig | 0.86 | 8.8 | 0.97 | KEV | Sep 15, 2021 | Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An attacker could craft… | |
| CVE-2021-34527 | Hig | 0.86 | 8.8 | 1.00 | KEV | Jul 2, 2021 | A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs;… | |
| CVE-2020-0688 | Hig | 0.86 | 8.8 | 1.00 | KEV | Feb 11, 2020 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'. | |
| CVE-2020-0618 | Hig | 0.86 | 8.8 | 0.99 | KEV | Feb 11, 2020 | A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'. |
- risk 0.94cvss 10.0epss 1.00
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
- risk 0.93cvss 9.8epss 1.00
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update…
- risk 0.93cvss 9.8epss 1.00
Microsoft SharePoint Server Elevation of Privilege Vulnerability
- risk 0.93cvss 9.8epss 1.00
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
- risk 0.93cvss 9.8epss 1.00
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution…
- risk 0.93cvss 9.8epss 1.00
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.
- risk 0.88cvss 9.1epss 1.00
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.88cvss 9.1epss 1.00
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.87cvss 9.8epss 1.00
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
- risk 0.87cvss 9.0epss 1.00
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.87cvss 9.8epss 1.00
HTTP Protocol Stack Remote Code Execution Vulnerability
- risk 0.87cvss 9.8epss 0.99
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
- risk 0.87cvss 9.8epss 1.00
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."
- risk 0.87cvss 9.8epss 0.99
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as…
- risk 0.86cvss 8.8epss 1.00
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.86cvss 8.8epss 1.00
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.86cvss 8.8epss 0.97
Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An attacker could craft…
- risk 0.86cvss 8.8epss 1.00
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs;…
- risk 0.86cvss 8.8epss 1.00
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
- risk 0.86cvss 8.8epss 0.99
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.