56.742 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.477 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-21353 | HIGH 8.8 | microsoft windows_server_2022_23h2 Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2022-23261 | MED 5.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Tampering Vulnerability | 1,6% | — |
| CVE-2020-0663 | MED 4.2 | microsoft edge An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacke | 1,6% | — |
| CVE-2011-0043 | HIGH 7.2 | microsoft windows_2003_server Kerberos in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 supports weak hashing algorithms, which allows local users to gain privileges by operating a service that sends crafted service tickets, as demonstrated by the CRC32 algorithm, aka "Kerberos Unke | 1,6% | — |
| CVE-2022-37972 | HIGH 7.5 | microsoft endpoint_configuration_manager Microsoft Endpoint Configuration Manager Spoofing Vulnerability | 1,6% | — |
| CVE-2010-0026 | MED 4.0 | microsoft windows_server_2008 The Hyper-V server implementation in Microsoft Windows Server 2008 Gold, SP2, and R2 on the x64 platform allows guest OS users to cause a denial of service (host OS hang) via a crafted application that executes a malformed series of machine instructions, aka " | 1,6% | — |
| CVE-2022-41127 | HIGH 8.5 | microsoft dynamics_365_business_central Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability | 1,6% | — |
| CVE-2024-49082 | MED 6.8 | microsoft windows_10_1507 Windows File Explorer Information Disclosure Vulnerability | 1,6% | — |
| CVE-2024-38214 | MED 6.5 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | 1,6% | — |
| CVE-2021-28478 | HIGH 7.6 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1,6% | — |
| CVE-2023-23388 | HIGH 8.8 | microsoft windows_10_1507 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 1,6% | — |
| CVE-2018-8650 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoi | 1,6% | — |
| CVE-2022-30170 | HIGH 7.3 | microsoft windows_10 Windows Credential Roaming Service Elevation of Privilege Vulnerability | 1,6% | — |
| CVE-2020-1454 | MED 5.4 | microsoft sharepoint_enterprise_server This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePo | 1,6% | — |
| CVE-2020-1326 | MED 5.4 | microsoft azure_devops_server A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'. | 1,6% | — |
| CVE-2017-8627 | MED 4.7 | microsoft windows_10 Windows Subsystem for Linux in Windows 10 1703, allows a denial of service vulnerability due to the way it handles objects in memory, aka "Windows Subsystem for Linux Denial of Service Vulnerability". | 1,6% | — |
| CVE-2025-47172 | HIGH 8.8 | microsoft sharepoint_enterprise_server Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1,6% | — |
| CVE-2025-21301 | MED 6.5 | microsoft windows_10_1507 Windows Geolocation Service Information Disclosure Vulnerability | 1,6% | — |
| CVE-2019-0707 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it.To exploit the vulnerability, in a local attack scenario, an attacker could ru | 1,6% | — |
| CVE-2017-8675 | HIGH 7.0 | microsoft windows_10 The Windows Kernel-Mode Drivers component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privil | 1,6% | — |
| CVE-2023-35622 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 1,6% | — |
| CVE-2017-0169 | MED 5.4 | microsoft windows_8.1 An information disclosure vulnerability exists when Windows Hyper-V running on a Windows 8.1, Windows Server 2012. or Windows Server 2012 R2 host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Hyp | 1,6% | — |
| CVE-2016-0087 | HIGH 7.8 | microsoft windows_7 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 do not properly validate handles, which allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability." | 1,6% | — |
| CVE-2025-33068 | HIGH 7.5 | microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | 1,6% | — |
| CVE-2025-32725 | HIGH 7.5 | microsoft windows_server_2016 Protection mechanism failure in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1,6% | — |