EN
56.855 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

Vulnerabilità Microsoft

15.479 CVE

Vulnerabilità Microsoft
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2026-47640 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0,5%
CVE-2026-47638 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0,5%
CVE-2026-47637 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0,5%
CVE-2026-45483 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network. 0,5%
CVE-2026-45479 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0,5%
CVE-2026-45468 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0,5%
CVE-2026-45467 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0,5%
CVE-2026-45462 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0,5%
CVE-2026-20944 HIGH 8.4 microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0,5%
CVE-2025-48812 MED 5.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. 0,5%
CVE-2025-26678 HIGH 8.4 microsoft windows_10_1809 Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally. 0,5%
CVE-2022-37986 HIGH 7.8 microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability 0,5%
CVE-2021-34471 HIGH 7.8 microsoft malware_protection_engine Microsoft Defender Elevation of Privilege Vulnerability 0,5%
CVE-2026-55015 MED 5.5 microsoft remote_help Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally. 0,5%
CVE-2026-57990 HIGH 7.4 microsoft edge_chromium Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. 0,5%
CVE-2025-53736 MED 6.8 microsoft 365_apps Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. 0,5%
CVE-2023-35341 MED 6.2 microsoft windows_10_1507 Microsoft DirectMusic Information Disclosure Vulnerability 0,5%
CVE-2022-41054 HIGH 7.8 microsoft windows_10 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability 0,5%
CVE-2026-65802 HIGH 7.4 microsoft edge_chromium External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. 0,5%
CVE-2026-57097 MED 6.4 microsoft windows_10_1607 Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack. 0,5%
CVE-2026-42827 MED 6.5 microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. 0,5%
CVE-2025-21382 HIGH 7.8 microsoft windows_10_1809 Windows Graphics Component Elevation of Privilege Vulnerability 0,5%
CVE-2026-50370 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. 0,5%
CVE-2025-60709 HIGH 7.8 microsoft windows_10_1607 Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 0,5%
CVE-2023-35332 MED 6.8 microsoft windows_10_1507 Windows Remote Desktop Protocol Security Feature Bypass 0,5%