56.706 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.471 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2015-2478 | HIGH 7.2 | microsoft windows_10 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application that t | 1,9% | — |
| CVE-2015-2550 | HIGH 7.2 | microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka | 1,9% | — |
| CVE-2024-38091 | HIGH 7.5 | microsoft windows_10_1507 Microsoft WS-Discovery Denial of Service Vulnerability | 1,9% | — |
| CVE-2022-44708 | HIGH 8.3 | microsoft edge Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1,9% | — |
| CVE-2022-33667 | MED 6.5 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 1,9% | — |
| CVE-2023-35339 | HIGH 7.5 | microsoft windows_10_1507 Windows CryptoAPI Denial of Service Vulnerability | 1,9% | — |
| CVE-2022-35840 | HIGH 8.8 | microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2022-35836 | HIGH 8.8 | microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2022-35835 | HIGH 8.8 | microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2022-35834 | HIGH 8.8 | microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2022-34733 | HIGH 8.8 | microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2022-34731 | HIGH 8.8 | microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2025-55693 | HIGH 7.4 | microsoft windows_11_24h2 Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | 1,9% | — |
| CVE-2022-41115 | MED 6.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability | 1,9% | — |
| CVE-2022-29143 | HIGH 7.5 | microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability | 1,9% | — |
| CVE-2020-1145 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arb | 1,9% | — |
| CVE-2020-1141 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arb | 1,9% | — |
| CVE-2019-1195 | MED 4.2 | microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 1,9% | — |
| CVE-2019-1141 | MED 4.2 | microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 1,9% | — |
| CVE-2019-1131 | MED 4.2 | microsoft edge A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context | 1,9% | — |
| CVE-2020-1573 | MED 5.5 | microsoft sharepoint_designer A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra | 1,9% | — |
| CVE-2019-0713 | MED 6.8 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest oper | 1,9% | — |
| CVE-2019-0711 | MED 6.8 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest oper | 1,9% | — |
| CVE-2019-0710 | MED 6.8 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest oper | 1,9% | — |
| CVE-2023-29347 | HIGH 8.7 | microsoft windows_admin_center Windows Admin Center Spoofing Vulnerability | 1,9% | — |