56.706 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.471 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2022-39344 | CRIT 9.8 | microsoft azure_rtos_usbx Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. Prior to version 6.1.12, the USB DFU UPLOAD functionality may be utilized to introduce a buffer overflow resulting in overwrite of memo | 2,0% | — |
| CVE-2016-3231 | HIGH 7.8 | microsoft windows_diagnostics_hub The Standard Collector service in Windows Diagnostics Hub mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Windows Diagnostics Hub Elevation of Privilege Vulnerability." | 2,0% | — |
| CVE-2022-21987 | HIGH 8.0 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 2,0% | — |
| CVE-2025-27479 | HIGH 7.5 | microsoft windows_server_2012 Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network. | 2,0% | — |
| CVE-2025-27473 | HIGH 7.5 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. | 2,0% | — |
| CVE-2022-30221 | HIGH 8.8 | microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2020-0758 | HIGH 7.5 | microsoft azure_devops_server An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability'. This CVE ID is unique from | 2,0% | — |
| CVE-2026-33840 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 2,0% | — |
| CVE-2019-1442 | MED 5.5 | microsoft sharepoint_server A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerab | 2,0% | — |
| CVE-2020-1195 | LOW 3.1 | microsoft edge An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly validates input. An attacker who successfully exploited this vulnerability could write files to arbitrary locations and gain elevated privi | 2,0% | — |
| CVE-2022-24460 | HIGH 7.0 | microsoft windows_10 Tablet Windows User Interface Application Elevation of Privilege Vulnerability | 2,0% | — |
| CVE-2024-43609 | MED 6.5 | microsoft 365_apps Microsoft Office Spoofing Vulnerability | 2,0% | — |
| CVE-2023-36567 | HIGH 7.5 | microsoft windows_10_1507 Windows Deployment Services Information Disclosure Vulnerability | 2,0% | — |
| CVE-2023-29348 | HIGH 7.5 | microsoft windows_server_2008 Windows Remote Desktop Gateway (RD Gateway) Information Disclosure Vulnerability | 2,0% | — |
| CVE-2023-21757 | HIGH 7.5 | microsoft windows_10 Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability | 2,0% | — |
| CVE-2022-30145 | HIGH 7.5 | microsoft windows_10 Windows Encrypting File System (EFS) Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2022-37976 | HIGH 8.8 | microsoft windows_server_2008 Active Directory Certificate Services Elevation of Privilege Vulnerability | 2,0% | — |
| CVE-2001-0048 | HIGH 7.2 | microsoft windows_2000 The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Rest | 2,0% | — |
| CVE-2015-0011 | MED 4.7 | microsoft windows_7 mrxdav.sys (aka the WebDAV driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow | 2,0% | — |
| CVE-2022-22024 | HIGH 7.8 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2026-42986 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 2,0% | — |
| CVE-2026-42905 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 2,0% | — |
| CVE-2017-0244 | MED 6.7 | microsoft windows_7 The kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows locally authenticated attackers to gain privileges via a crafted application, or in Windows 7 for x64-based systems, cause denial of service, aka "Windows Kernel Elevation of Privilege | 2,0% | — |
| CVE-2007-5470 | LOW 2.1 | microsoft expression_media Microsoft Expression Media stores the catalog password in cleartext in the catalog IVC file, which allows local users to obtain sensitive information and gain access to the catalog by reading the IVC file. | 2,0% | — |
| CVE-2013-3903 | MED 4.7 | microsoft windows_8 Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to cause a denial of service (reboot) via a crafted TrueType font (TTF) file, aka "TrueType Font | 2,0% | — |