EN
56.706 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

Vulnerabilità Microsoft

15.471 CVE

Vulnerabilità Microsoft
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2019-1167 MED 4.1 microsoft powershell_core A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'. 1,9%
CVE-2018-1039 HIGH 7.8 microsoft .net_framework A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, aka ".NET Framework Device Guard Security Feature Bypass Vulnerability." This affects Microsoft .NET Framework 4.7.1, Microsoft .NET Framewor 1,9%
CVE-2015-2361 HIGH 7.2 microsoft windows_8.1 Hyper-V in Microsoft Windows 8.1 and Windows Server 2012 R2 does not properly initialize guest OS system data structures, which allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (buffer overflow) by leveraging guest OS 1,9%
CVE-2025-26663 HIGH 8.1 microsoft windows_10_1507 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network. 1,9%
CVE-2020-17091 HIGH 7.8 microsoft teams Microsoft Teams Remote Code Execution Vulnerability 1,9%
CVE-2013-1332 HIGH 7.2 microsoft windows_7 dxgkrnl.sys (aka the DirectX graphics kernel subsystem) in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, whi 1,9%
CVE-2011-1886 LOW 2.1 microsoft windows_xp win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3 does not properly validate the arguments to functions, which allows local users to read arbitrary data from kernel memory via a crafted application that triggers a NULL pointer dereference, aka 1,9%
CVE-2003-0897 MED 4.6 microsoft windows_xp "Shatter" vulnerability in CommCtl32.dll in Windows XP may allow local users to execute arbitrary code by sending (1) BCM_GETTEXTMARGIN or (2) BCM_SETTEXTMARGIN button control messages to privileged applications. 1,9%
CVE-2019-0627 HIGH 7.8 microsoft powershell_core A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0631, CVE-2019-0632. 1,9%
CVE-2014-4074 HIGH 7.2 microsoft windows_8 The Task Scheduler in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via an application that schedules a crafted task, aka "Task Scheduler Vulnerability." 1,9%
CVE-2021-36945 HIGH 7.3 microsoft windows_10_update_assistant Windows 10 Update Assistant Elevation of Privilege Vulnerability 1,9%
CVE-2016-5720 HIGH 7.8 microsoft skype Multiple untrusted search path vulnerabilities in Microsoft Skype allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) msi.dll, (2) dpapi.dll, or (3) cryptui.dll that is located in the current working directory. 1,9%
CVE-2023-38156 HIGH 7.2 microsoft azure_hdinsight Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability 1,9%
CVE-2018-8612 MED 5.5 microsoft windows_10 A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values, aka "Connected User Experiences and Telemetry Service Denial of Service Vulnerability." This affects Windows Server 2016, 1,9%
CVE-2013-3167 HIGH 7.2 microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 does not properly handle objects in memory, which allows local users to gain privileges 1,9%
CVE-2024-38231 MED 6.5 microsoft windows_server_2008 Windows Remote Desktop Licensing Service Denial of Service Vulnerability 1,9%
CVE-2023-36890 MED 6.5 microsoft sharepoint_server Microsoft SharePoint Server Information Disclosure Vulnerability 1,9%
CVE-2020-17057 HIGH 7.0 microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability 1,9%
CVE-2023-33127 HIGH 8.1 microsoft .net .NET and Visual Studio Elevation of Privilege Vulnerability 1,9%
CVE-2022-26829 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 1,9%
CVE-2022-26822 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 1,9%
CVE-2022-26821 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 1,9%
CVE-2022-26820 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 1,9%
CVE-2022-26819 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 1,9%
CVE-2010-3222 HIGH 7.2 microsoft windows_server_2003 Stack-based buffer overflow in the Remote Procedure Call Subsystem (RPCSS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted LPC message that requests an LRPC connection from an LPC server to a client, 1,9%