56.864 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.479 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-49755 | MED 4.3 | microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | 0,5% | — |
| CVE-2024-28905 | HIGH 7.8 | microsoft windows_server_2022_23h2 Microsoft Brokering File System Elevation of Privilege Vulnerability | 0,5% | — |
| CVE-2026-0102 | LOW 3.1 | microsoft edge_chromium Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number | 0,5% | — |
| CVE-2025-29808 | MED 5.5 | microsoft windows_server_2022 Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-70355 | HIGH 7.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0,5% | — |
| CVE-2026-40380 | MED 6.2 | microsoft windows_10_1607 Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack. | 0,5% | — |
| CVE-2026-24285 | HIGH 7.0 | microsoft 365_copilot Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2026-26124 | MED 6.7 | microsoft aci_confidential_containers '.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2025-64669 | HIGH 7.8 | microsoft windows_admin_center Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2026-56161 | CRIT 9.6 | microsoft azure_logic_apps Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. | 0,5% | — |
| CVE-2026-54988 | MED 6.1 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-44801 | HIGH 7.5 | microsoft remote_desktop_client Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-44799 | HIGH 7.5 | microsoft remote_desktop_client Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-42992 | HIGH 7.5 | microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0,5% | — |
| CVE-2026-34329 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network. | 0,5% | — |
| CVE-2025-60708 | MED 6.5 | microsoft windows_10_1607 Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally. | 0,5% | — |
| CVE-2025-32703 | MED 5.5 | microsoft visual_studio_2017 Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2023-28276 | MED 4.4 | microsoft windows_10_1507 Windows Group Policy Security Feature Bypass Vulnerability | 0,5% | — |
| CVE-2026-25168 | MED 6.2 | microsoft windows_10_1607 Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally. | 0,5% | — |
| CVE-2025-49743 | MED 6.7 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2026-63530 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-42972 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2026-42971 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. | 0,5% | — |
| CVE-2025-64679 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 0,5% | — |
| CVE-2023-21767 | HIGH 7.8 | microsoft windows_10 Windows Overlay Filter Elevation of Privilege Vulnerability | 0,5% | — |