56.793 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.479 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-1638 | HIGH 7.7 | microsoft windows_10 Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software | 1,2% | — |
| CVE-2024-38108 | CRIT 9.3 | microsoft azure_stack_hub Azure Stack Hub Spoofing Vulnerability | 1,2% | — |
| CVE-2023-36788 | HIGH 7.8 | microsoft .net_framework .NET Framework Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2025-47957 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 1,2% | — |
| CVE-2024-49076 | HIGH 7.8 | microsoft windows_10_1809 Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | 1,2% | — |
| CVE-2023-36742 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2023-21685 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2023-24890 | MED 6.5 | microsoft onedrive Microsoft OneDrive for iOS Security Feature Bypass Vulnerability | 1,2% | — |
| CVE-2023-36022 | MED 6.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2022-23262 | MED 6.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1,2% | — |
| CVE-2024-29987 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 1,2% | — |
| CVE-2023-32021 | HIGH 7.1 | microsoft windows_server_2012 Windows SMB Witness Service Security Feature Bypass Vulnerability | 1,2% | — |
| CVE-2021-1670 | MED 5.5 | microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability | 1,2% | — |
| CVE-2021-1663 | MED 5.5 | microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability | 1,2% | — |
| CVE-2021-1637 | MED 5.5 | microsoft windows_10 Windows DNS Query Information Disclosure Vulnerability | 1,2% | — |
| CVE-2026-26119 | HIGH 8.8 | microsoft windows_admin_center Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | 1,2% | — |
| CVE-2026-20921 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 1,2% | — |
| CVE-2002-0725 | MED 5.5 | microsoft windows_2000 NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit trail instead of the target file. | 1,2% | — |
| CVE-2026-32225 | HIGH 8.8 | microsoft windows_10_1607 Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | 1,2% | — |
| CVE-2021-26892 | MED 6.2 | microsoft windows_10 Windows Extensible Firmware Interface Security Feature Bypass Vulnerability | 1,2% | — |
| CVE-2021-28483 | CRIT 9.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2020-17134 | HIGH 7.8 | microsoft windows_10 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 1,2% | — |
| CVE-2025-49666 | HIGH 7.2 | microsoft windows_server_2016 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network. | 1,2% | — |
| CVE-2026-42898 | CRIT 9.9 | microsoft dynamics_365 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | 1,2% | — |
| CVE-2025-32714 | HIGH 7.8 | microsoft windows_10_1507 Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally. | 1,2% | — |