56.707 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.471 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-21379 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 1,7% | — |
| CVE-1999-1556 | HIGH 7.2 | microsoft sql_server Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value. | 1,7% | — |
| CVE-2018-0983 | HIGH 7.0 | microsoft windows_10 Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Storage Services Elevation | 1,7% | — |
| CVE-2022-33680 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1,7% | — |
| CVE-2010-0719 | MED 4.7 | microsoft windows_2000 An unspecified API in Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 does not validate arguments, which allows local users to cause a denial of service (system crash) via a crafted application. | 1,7% | — |
| CVE-2024-30097 | HIGH 8.8 | microsoft windows_10_1507 Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability | 1,7% | — |
| CVE-2024-30009 | HIGH 8.8 | microsoft windows_10_1507 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1,7% | — |
| CVE-2024-30006 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1,7% | — |
| CVE-2020-1101 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra | 1,7% | — |
| CVE-2020-1100 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra | 1,7% | — |
| CVE-2020-1099 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra | 1,7% | — |
| CVE-2024-30076 | MED 6.8 | microsoft windows_10_1607 Windows Container Manager Service Elevation of Privilege Vulnerability | 1,7% | — |
| CVE-2017-0021 | CRIT 9.0 | microsoft windows_10 Hyper-V in Microsoft Windows 10 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary code on a target OS, aka "Hyper-V System Data Structure Vulnerability." This vulnerability is different from t | 1,7% | — |
| CVE-2011-1967 | HIGH 7.2 | microsoft windows_2003_server Winsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check p | 1,7% | — |
| CVE-2025-47987 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally. | 1,7% | — |
| CVE-2023-36911 | CRIT 9.8 | microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | 1,7% | — |
| CVE-2018-0750 | MED 5.5 | microsoft windows_7 The Windows GDI component in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Windows Elevation of Privilege Vulnerability". | 1,7% | — |
| CVE-2024-49080 | HIGH 8.8 | microsoft windows_10_1507 Windows IP Routing Management Snapin Remote Code Execution Vulnerability | 1,7% | — |
| CVE-2024-49057 | HIGH 8.1 | microsoft defender_for_endpoint Microsoft Defender for Endpoint on Android Spoofing Vulnerability | 1,7% | — |
| CVE-2007-1221 | HIGH 7.2 | microsoft xbox_360 The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 allows attackers with physical access to force execution of the hypervisor syscall with a certain register set, which bypasses intended code protection. | 1,7% | — |
| CVE-2024-37965 | HIGH 8.8 | microsoft sql_server_2016 Microsoft SQL Server Elevation of Privilege Vulnerability | 1,7% | — |
| CVE-2020-16991 | HIGH 7.3 | microsoft azure_sphere Azure Sphere Unsigned Code Execution Vulnerability | 1,7% | — |
| CVE-2011-2010 | HIGH 7.2 | microsoft pinyin_ime The Microsoft Office Input Method Editor (IME) for Simplified Chinese in Microsoft Pinyin IME 2010, Office Pinyin SimpleFast Style 2010, and Office Pinyin New Experience Style 2010 does not properly restrict access to configuration options, which allows local | 1,7% | — |
| CVE-2005-1982 | LOW 3.6 | microsoft windows_2000 Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when P | 1,7% | — |
| CVE-2001-0547 | LOW 2.1 | microsoft isa_server Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion). | 1,7% | — |