56.706 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.471 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2013-3173 | HIGH 7.2 | microsoft windows_7 Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to ga | 2,0% | — |
| CVE-2020-1595 | CRIT 9.9 | microsoft sharepoint_enterprise_server <p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application | 2,0% | — |
| CVE-2019-1440 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1436. | 2,0% | — |
| CVE-2022-38006 | MED 6.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 2,0% | — |
| CVE-2026-62741 | HIGH 7.8 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | 2,0% | — |
| CVE-2026-61930 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 2,0% | — |
| CVE-2023-36437 | HIGH 8.8 | microsoft azure_pipelines_agent Azure DevOps Server Remote Code Execution Vulnerability | 2,0% | — |
| CVE-2015-2454 | LOW 2.1 | microsoft windows_7 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels, which allows local | 2,0% | — |
| CVE-2026-62713 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 1,9% | — |
| CVE-2021-34517 | MED 5.3 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1,9% | — |
| CVE-2021-3339 | MED 4.3 | microsoft modernflow ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen. | 1,9% | — |
| CVE-2022-37959 | MED 6.5 | microsoft windows_server_2012 Network Device Enrollment Service (NDES) Security Feature Bypass Vulnerability | 1,9% | — |
| CVE-2002-0034 | MED 4.6 | microsoft windows_2000 The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than ex | 1,9% | — |
| CVE-2025-21217 | MED 6.5 | microsoft windows_10_1507 Windows NTLM Spoofing Vulnerability | 1,9% | — |
| CVE-2022-35802 | HIGH 8.1 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 1,9% | — |
| CVE-2024-26161 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2024-26159 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2024-21451 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2024-21444 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2024-21441 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2022-33655 | MED 6.5 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 1,9% | — |
| CVE-2017-8494 | HIGH 7.3 | microsoft windows_10 Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a locally-authenticated attacker to run a specially crafted application on a targeted system when Windows Secure Kernel Mode fails to properly handle objects in memory, aka "Windows | 1,9% | — |
| CVE-2020-1044 | MED 4.3 | microsoft sql_server_reporting_services <p>A security feature bypass vulnerability exists in SQL Server Reporting Services (SSRS) when the server improperly validates attachments uploaded to reports. An attacker who successfully exploited this vulnerability could upload file types that were disallow | 1,9% | — |
| CVE-2019-1198 | MED 6.5 | microsoft windows_10 An elevation of privilege exists in SyncController.dll. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could e | 1,9% | — |
| CVE-2023-32014 | CRIT 9.8 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | 1,9% | — |