56.932 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.479 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-26107 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-59222 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-29833 | HIGH 7.7 | microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows Virtual Machine Bus allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-42993 | HIGH 7.5 | microsoft windows_10_21h2 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0,4% | — |
| CVE-2025-48815 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows SSDP Service allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2024-49084 | HIGH 7.0 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-21561 | HIGH 7.8 | microsoft windows_10_1607 Microsoft Cryptographic Services Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-21551 | HIGH 7.8 | microsoft windows_10_1809 Microsoft Cryptographic Services Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2026-26133 | HIGH 7.1 | microsoft 365_copilot AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 0,4% | — |
| CVE-2025-48809 | MED 5.5 | microsoft windows_11_24h2 Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-48565 | HIGH 7.8 | microsoft windows_narrator_braille Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-27478 | HIGH 7.0 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2024-38179 | HIGH 8.8 | microsoft azure_stack_hci Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-36721 | HIGH 7.0 | microsoft windows_10_1809 Windows Error Reporting Service Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2026-58290 | HIGH 7.5 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0,4% | — |
| CVE-2026-21508 | HIGH 7.0 | microsoft windows_10_1607 Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-32726 | MED 6.8 | microsoft visual_studio_code Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-20928 | MED 4.6 | microsoft windows_10_1607 Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack. | 0,4% | — |
| CVE-2026-24288 | MED 6.8 | microsoft windows_10_21h2 Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical attack. | 0,4% | — |
| CVE-2025-55680 | HIGH 7.8 | microsoft windows_10_1809 Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-53725 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-53154 | HIGH 7.8 | microsoft windows_10_1507 Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-53151 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-53141 | HIGH 7.8 | microsoft windows_10_1507 Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-50155 | HIGH 7.8 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. | 0,4% | — |