56.793 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.479 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2017-11782 | HIGH 7.8 | microsoft windows_10 The Microsoft Server Block Message (SMB) on Microsoft Windows 10 1607 and Windows Server 2016, allows an elevation of privilege vulnerability when an attacker sends specially crafted requests to the server, aka "Windows SMB Elevation of Privilege Vulnerability | 1,2% | — |
| CVE-2017-8503 | HIGH 8.8 | microsoft edge Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to escape from the AppContainer sandbox, aka "Microsoft Edge Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8642. | 1,2% | — |
| CVE-2011-1236 | HIGH 7.8 | microsoft windows_2003_server Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain | 1,2% | — |
| CVE-2023-36871 | MED 6.5 | microsoft windows_10_1507 Azure Active Directory Security Feature Bypass Vulnerability | 1,2% | — |
| CVE-2011-1887 | HIGH 7.8 | microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a | 1,2% | — |
| CVE-2025-27481 | HIGH 8.8 | microsoft windows_10_1507 Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network. | 1,2% | — |
| CVE-2025-27471 | MED 5.9 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network. | 1,2% | — |
| CVE-2023-29352 | MED 6.5 | microsoft remote_desktop_client Windows Remote Desktop Security Feature Bypass Vulnerability | 1,2% | — |
| CVE-1999-0824 | MED 4.6 | microsoft windows_nt A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users. | 1,2% | — |
| CVE-1999-0384 | MED 4.6 | microsoft office The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content. | 1,2% | — |
| CVE-2025-24994 | HIGH 7.3 | microsoft windows_11_22h2 Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally. | 1,2% | — |
| CVE-2013-1283 | MED 6.9 | microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows loca | 1,2% | — |
| CVE-2023-28290 | MED 5.3 | microsoft remote_desktop_app Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability | 1,2% | — |
| CVE-2022-30175 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 1,2% | — |
| CVE-2021-26431 | HIGH 7.8 | microsoft windows_10 Windows Recovery Environment Agent Elevation of Privilege Vulnerability | 1,2% | — |
| CVE-2020-1398 | MED 6.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly handle Ease of Access dialog.An attacker who successfully exploited the vulnerability could execute commands with elevated permissions.The security update addresses the vu | 1,2% | — |
| CVE-2019-1065 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, | 1,2% | — |
| CVE-2017-11818 | MED 4.5 | microsoft windows_10 The Microsoft Windows Storage component on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass vulnerability when it fails to validate an integrity-level | 1,2% | — |
| CVE-2026-54118 | CRIT 9.8 | microsoft sql_server_2016 Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | 1,2% | — |
| CVE-2026-54117 | CRIT 9.8 | microsoft sql_server_2016 Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | 1,2% | — |
| CVE-2026-35435 | HIGH 8.6 | microsoft azure_ai_foundry Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. | 1,2% | — |
| CVE-2024-38089 | CRIT 9.1 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 1,2% | — |
| CVE-2023-28271 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 1,2% | — |
| CVE-2022-23269 | MED 5.4 | microsoft dynamics_gp Microsoft Dynamics GP Spoofing Vulnerability | 1,2% | — |
| CVE-2020-24003 | LOW 3.3 | microsoft skype Microsoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Skype Cli | 1,2% | — |