56.793 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.479 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-54119 | HIGH 7.5 | microsoft windows_10_1607 Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-50696 | HIGH 7.5 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-50695 | HIGH 7.5 | microsoft windows_10_1607 Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-50653 | HIGH 7.5 | microsoft .net_framework Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-50506 | HIGH 7.5 | microsoft asp.net_core_odata Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-49788 | HIGH 7.5 | microsoft windows_10_1607 Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-49787 | HIGH 7.5 | microsoft windows_10_1607 Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-45646 | HIGH 7.5 | microsoft asp.net_core_odata Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-44806 | MED 5.3 | microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2026-40378 | HIGH 7.5 | microsoft windows_10_1607 Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2023-29335 | HIGH 7.5 | microsoft 365_apps Microsoft Word Security Feature Bypass Vulnerability | 1,2% | — |
| CVE-2018-0868 | HIGH 7.0 | microsoft windows_10 Windows Installer in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privi | 1,2% | — |
| CVE-2018-0809 | HIGH 7.0 | microsoft windows_10 The Windows kernel in Windows 10, versions 1703 and 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Elevation of Privilege Vulnerability". This CVE is unique from | 1,2% | — |
| CVE-2024-21325 | HIGH 7.8 | microsoft printer_metadata_troubleshooter_tool Microsoft Printer Metadata Troubleshooter Tool Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2022-41061 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2020-17102 | MED 5.5 | microsoft webp_image_extension WebP Image Extensions Information Disclosure Vulnerability | 1,2% | — |
| CVE-2011-0676 | HIGH 7.8 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted applica | 1,2% | — |
| CVE-2026-49181 | HIGH 7.5 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network. | 1,2% | — |
| CVE-2024-21376 | CRIT 9.0 | microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2026-26125 | HIGH 8.6 | microsoft payment_orchestrator_service Payment Orchestrator Service Elevation of Privilege Vulnerability | 1,2% | — |
| CVE-2025-26646 | HIGH 8.0 | microsoft .net External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. | 1,2% | — |
| CVE-2025-21417 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2024-38184 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 1,2% | — |
| CVE-2024-0056 | HIGH 8.7 | microsoft .net Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability | 1,2% | — |
| CVE-2018-0756 | HIGH 7.8 | microsoft windows_10 The Windows kernel in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Kernel Elevation of Privilege Vulne | 1,2% | — |