56.742 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.477 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-28268 | HIGH 8.1 | microsoft windows_server_2008 Netlogon RPC Elevation of Privilege Vulnerability | 1,5% | — |
| CVE-2023-21708 | CRIT 9.8 | microsoft windows_10_1507 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 1,5% | — |
| CVE-2016-3287 | MED 4.4 | microsoft windows_10 Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Secure Boot protection mechanism by leveraging administrative access to install a crafted policy, aka "Secure Boot Security Fe | 1,5% | — |
| CVE-2016-0180 | HIGH 7.8 | microsoft windows_10 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles symbolic links, which allows local users to gain privileges via | 1,5% | — |
| CVE-2023-36425 | HIGH 8.0 | microsoft windows_10_1507 Windows Distributed File System (DFS) Remote Code Execution Vulnerability | 1,5% | — |
| CVE-2020-17113 | MED 5.5 | microsoft windows_10 Windows Camera Codec Information Disclosure Vulnerability | 1,5% | — |
| CVE-2019-1163 | MED 5.5 | microsoft windows_10 A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker who successfully exploited this vulnerability could inject code into a CAB file without invalidating the file's signature. To exploit the vulnerability, an att | 1,5% | — |
| CVE-2024-21350 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1,5% | — |
| CVE-2022-21838 | MED 5.5 | microsoft windows_10 Windows Cleanup Manager Elevation of Privilege Vulnerability | 1,5% | — |
| CVE-2001-0350 | MED 4.6 | microsoft windows_2000 Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program wi | 1,5% | — |
| CVE-2019-1486 | MED 6.1 | microsoft visual_studio_2019 A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host, aka 'Visual Studio Live Share Spoofing Vulnerability'. | 1,5% | — |
| CVE-2025-47962 | HIGH 7.8 | microsoft windows_software_development_kit Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally. | 1,5% | — |
| CVE-2020-17046 | MED 5.5 | microsoft windows_10 Windows Error Reporting Denial of Service Vulnerability | 1,5% | — |
| CVE-2019-0942 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists in the Unified Write Filter (UWF) feature for Windows 10 when it improperly restricts access to the registry, aka 'Unified Write Filter Elevation of Privilege Vulnerability'. | 1,5% | — |
| CVE-2018-8641 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows | 1,5% | — |
| CVE-2000-0777 | HIGH 7.2 | microsoft money The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the "Money Password" vulnerability. | 1,5% | — |
| CVE-2020-1474 | HIGH 7.8 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service improperly discloses contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s syst | 1,5% | — |
| CVE-2000-0259 | HIGH 7.2 | microsoft terminal_server The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users. | 1,5% | — |
| CVE-2025-33056 | HIGH 7.5 | microsoft windows_10_1507 Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network. | 1,5% | — |
| CVE-2025-26676 | MED 6.5 | microsoft windows_server_2008 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1,5% | — |
| CVE-2024-21316 | MED 6.1 | microsoft windows_10_1607 Windows Server Key Distribution Service Security Feature Bypass | 1,5% | — |
| CVE-2022-41048 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1,5% | — |
| CVE-2022-41047 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1,5% | — |
| CVE-2022-37978 | HIGH 7.5 | microsoft windows_10 Windows Active Directory Certificate Services Security Feature Bypass | 1,5% | — |
| CVE-2020-1049 | MED 5.4 | microsoft dynamics_365_server A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. This | 1,5% | — |