56.706 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.471 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2008-4540 | LOW 2.1 | microsoft windows_mobile Windows Mobile 6 on the HTC Hermes device makes WLAN passwords available to an auto-completion mechanism for the password input field, which allows physically proximate attackers to bypass password authentication and obtain WLAN access. | 2,0% | — |
| CVE-2022-41056 | HIGH 7.5 | microsoft windows_10 Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability | 2,0% | — |
| CVE-2019-1266 | MED 6.1 | microsoft exchange_server A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. | 2,0% | — |
| CVE-2024-49019 | HIGH 7.8 | microsoft windows_server_2008 Active Directory Certificate Services Elevation of Privilege Vulnerability | 2,0% | — |
| CVE-2023-29330 | HIGH 8.8 | microsoft teams Microsoft Teams Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2022-35774 | MED 4.9 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 2,0% | — |
| CVE-2021-43255 | MED 5.5 | microsoft 365_apps Microsoft Office Trust Center Spoofing Vulnerability | 2,0% | — |
| CVE-2024-21307 | HIGH 7.5 | microsoft windows_10_1507 Remote Desktop Client Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2022-35744 | CRIT 9.8 | microsoft windows_10_1507 Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2018-8165 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 | 2,0% | — |
| CVE-2023-33170 | HIGH 8.1 | fedoraproject fedora ASP.NET and Visual Studio Security Feature Bypass Vulnerability | 2,0% | — |
| CVE-2023-21728 | HIGH 7.5 | microsoft windows_10_1607 Windows Netlogon Denial of Service Vulnerability | 2,0% | — |
| CVE-2023-21683 | HIGH 7.5 | microsoft windows_10_1607 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | 2,0% | — |
| CVE-2023-21677 | HIGH 7.5 | microsoft windows_10_1607 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | 2,0% | — |
| CVE-2023-21527 | HIGH 7.5 | microsoft windows_10_1607 Windows iSCSI Service Denial of Service Vulnerability | 2,0% | — |
| CVE-2021-33746 | HIGH 8.0 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2021-1639 | HIGH 7.0 | microsoft visual_studio_2017 Visual Studio Code Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2026-40368 | HIGH 8.0 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 2,0% | — |
| CVE-2013-5046 | MED 6.2 | microsoft internet_explorer Microsoft Internet Explorer 7 through 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability." | 2,0% | — |
| CVE-2023-36787 | HIGH 8.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 2,0% | — |
| CVE-2021-1726 | HIGH 8.0 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 2,0% | — |
| CVE-2023-36906 | MED 5.5 | microsoft windows_10 Windows Cryptographic Services Information Disclosure Vulnerability | 2,0% | — |
| CVE-2010-1889 | HIGH 7.8 | microsoft windows_server_2008 Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka "Windows Kernel D | 2,0% | — |
| CVE-2019-0558 | MED 5.4 | microsoft business_productivity_servers A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoi | 2,0% | — |
| CVE-2011-2018 | HIGH 7.2 | microsoft windows_7 The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, and Windows 7 Gold and SP1 does not properly initialize objects, which allows local users to gain privileges via a crafted application, aka "Wi | 2,0% | — |