56.775 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.477 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-29362 | HIGH 8.8 | microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2024-38212 | HIGH 8.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2011-0671 | HIGH 8.4 | microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain | 1,3% | — |
| CVE-2009-1922 | MED 6.9 | microsoft windows_2000 The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain pr | 1,3% | — |
| CVE-2024-43517 | HIGH 8.8 | microsoft windows_10_1507 Microsoft ActiveX Data Objects Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2024-29066 | HIGH 7.2 | microsoft windows_server_2008 Windows Distributed File System (DFS) Remote Code Execution Vulnerability | 1,3% | — |
| CVE-2010-0484 | MED 6.8 | microsoft windows_2000 The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 "do not properly validate changes in certain kernel objects," which allows local users to execute arbi | 1,3% | — |
| CVE-1999-1370 | HIGH 7.2 | microsoft internet_explorer The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prev | 1,3% | — |
| CVE-2005-0921 | MED 4.6 | microsoft outlook_connector Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy. | 1,3% | — |
| CVE-2023-32042 | MED 6.5 | microsoft windows_10_1507 OLE Automation Information Disclosure Vulnerability | 1,3% | — |
| CVE-2024-43583 | HIGH 7.8 | microsoft windows_10_1507 Winlogon Elevation of Privilege Vulnerability | 1,3% | — |
| CVE-2019-1090 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the dnsrslvr.dll handles objects in memory, aka 'Windows dnsrlvr.dll Elevation of Privilege Vulnerability'. | 1,3% | — |
| CVE-2019-1067 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. | 1,3% | — |
| CVE-2019-0999 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. | 1,3% | — |
| CVE-2026-21243 | HIGH 7.5 | microsoft windows_server_2019 Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network. | 1,3% | — |
| CVE-2026-20846 | HIGH 7.5 | microsoft windows_10_1607 Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network. | 1,3% | — |
| CVE-2003-1482 | MED 4.6 | microsoft mn-500_wireless_base_station The backup configuration file for Microsoft MN-500 wireless base station stores administrative passwords in plaintext, which allows local users to gain access. | 1,3% | — |
| CVE-2025-55227 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1,3% | — |
| CVE-2024-21403 | CRIT 9.0 | microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | 1,3% | — |
| CVE-2019-1282 | MED 5.5 | microsoft windows_10 An information disclosure exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle sandbox checks, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'. | 1,3% | — |
| CVE-2019-1274 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. | 1,3% | — |
| CVE-2025-29807 | HIGH 8.7 | microsoft dataverse Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. | 1,3% | — |
| CVE-2024-20679 | MED 6.5 | microsoft azure_stack_hub Azure Stack Hub Spoofing Vulnerability | 1,3% | — |
| CVE-2021-36959 | MED 5.5 | microsoft windows_10 Windows Authenticode Spoofing Vulnerability | 1,3% | — |
| CVE-2024-43581 | HIGH 7.1 | microsoft windows_10_1809 Microsoft OpenSSH for Windows Remote Code Execution Vulnerability | 1,3% | — |