56.932 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.479 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-53734 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2023-24946 | HIGH 7.8 | microsoft windows_10_1507 Windows Backup Service Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2026-49177 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-32085 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-48818 | MED 6.8 | microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0,4% | — |
| CVE-2025-29816 | HIGH 7.5 | microsoft 365_apps Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network. | 0,4% | — |
| CVE-2022-33644 | HIGH 7.0 | microsoft windows_10 Xbox Live Save Service Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2026-72984 | HIGH 8.8 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0,4% | — |
| CVE-2026-69555 | CRIT 10.0 | microsoft azure_arc Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | 0,4% | — |
| CVE-2026-65807 | HIGH 8.8 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. | 0,4% | — |
| CVE-2026-58283 | HIGH 8.1 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2025-59198 | MED 5.0 | microsoft windows_10_1507 Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally. | 0,4% | — |
| CVE-2025-53147 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-48821 | HIGH 7.1 | microsoft windows_10_1507 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network. | 0,4% | — |
| CVE-2025-21325 | HIGH 7.8 | microsoft windows_10_21h2 Windows Secure Kernel Mode Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2022-24525 | HIGH 7.0 | microsoft windows_10 Windows Update Stack Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2026-47292 | HIGH 7.8 | microsoft visual_studio_code Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-32171 | HIGH 8.8 | microsoft azure_logic_apps Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. | 0,4% | — |
| CVE-2026-26179 | HIGH 7.8 | microsoft windows_11_23h2 Double free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-30393 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-65657 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-26117 | HIGH 7.8 | microsoft arc_enabled_servers_azure_connected_machine_agent Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-53726 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-53724 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-53152 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally. | 0,4% | — |