56.742 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.477 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-31964 | HIGH 7.6 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1,5% | — |
| CVE-2001-0005 | MED 6.2 | microsoft powerpoint Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands. | 1,5% | — |
| CVE-2023-36018 | HIGH 7.8 | microsoft jupyter Visual Studio Code Jupyter Extension Spoofing Vulnerability | 1,5% | — |
| CVE-2023-21676 | HIGH 8.8 | microsoft windows_10_1809 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1,5% | — |
| CVE-2019-0931 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations, aka 'Windows Storage Service Elevation of Privilege Vulnerability'. | 1,5% | — |
| CVE-2024-26192 | HIGH 8.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 1,5% | — |
| CVE-2023-21525 | MED 5.3 | microsoft windows_10_1607 Remote Procedure Call Runtime Denial of Service Vulnerability | 1,5% | — |
| CVE-1999-0534 | MED 4.6 | microsoft windows_2000 A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Increase Priority, Increase Quota, Load Driv | 1,5% | — |
| CVE-2024-49125 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1,5% | — |
| CVE-2024-49105 | HIGH 8.4 | microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability | 1,5% | — |
| CVE-2024-21305 | MED 4.4 | microsoft windows_10_1809 Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability | 1,5% | — |
| CVE-2020-1591 | MED 5.4 | microsoft dynamics_365 A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially cr | 1,5% | — |
| CVE-2020-0891 | MED 5.4 | microsoft sharepoint_enterprise_server This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePo | 1,5% | — |
| CVE-2004-2730 | MED 4.6 | microsoft psexec Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend | 1,5% | — |
| CVE-2022-21891 | HIGH 7.6 | microsoft dynamics_365_sales Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability | 1,5% | — |
| CVE-2022-21839 | MED 6.1 | microsoft windows_10 Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability | 1,5% | — |
| CVE-2020-1377 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. A locally authenticated atta | 1,5% | — |
| CVE-2024-26231 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1,5% | — |
| CVE-2024-26227 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1,5% | — |
| CVE-2002-1692 | LOW 3.6 | microsoft windows_95 Buffer overflow in backup utility of Microsoft Windows 95 allows attackers to execute arbitrary code by causing a filename with a long extension to be placed in a folder to be backed up. | 1,5% | — |
| CVE-2025-27491 | HIGH 7.1 | microsoft windows_10_1507 Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network. | 1,5% | — |
| CVE-2025-21380 | HIGH 8.8 | microsoft azure_marketplace Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network. | 1,5% | — |
| CVE-2023-36873 | HIGH 7.4 | microsoft .net_framework .NET Framework Spoofing Vulnerability | 1,5% | — |
| CVE-2025-21203 | MED 6.5 | microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1,5% | — |
| CVE-2023-24881 | MED 6.5 | microsoft teams Microsoft Teams Information Disclosure Vulnerability | 1,5% | — |