56.932 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.479 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-21362 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Security Feature Bypass Vulnerability | 0,4% | — |
| CVE-2026-32081 | MED 5.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-20949 | HIGH 7.8 | microsoft 365_apps Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. | 0,4% | — |
| CVE-2025-59243 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-55236 | HIGH 7.3 | microsoft windows_10_1809 Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-29842 | HIGH 7.5 | microsoft windows_10_1507 Acceptance of extraneous untrusted data with trusted data in UrlMon allows an unauthorized attacker to bypass a security feature over a network. | 0,4% | — |
| CVE-2025-24049 | HIGH 8.4 | microsoft azure_command-line_interface Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2023-21804 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2026-70335 | HIGH 7.8 | microsoft visual_studio_code Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-68798 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-41611 | HIGH 7.8 | microsoft visual_studio_code Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-41134 | HIGH 7.8 | microsoft kiota Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/query parameter mappings | 0,4% | — |
| CVE-2026-32215 | MED 5.5 | microsoft windows_10_1809 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-24282 | MED 5.5 | microsoft windows_10_1607 Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-26684 | MED 6.7 | microsoft defender_for_endpoint External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2024-49059 | HIGH 7.0 | microsoft 365_apps Microsoft Office Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2026-41090 | CRIT 9.3 | microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | 0,4% | — |
| CVE-2026-32217 | MED 5.5 | microsoft windows_10_1607 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-59203 | MED 5.5 | microsoft windows_10_1507 Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-59197 | MED 5.5 | microsoft windows_10_1507 Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-53730 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-32704 | HIGH 8.4 | microsoft 365_apps Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2024-21381 | MED 6.8 | microsoft azure_active_directory Microsoft Azure Active Directory B2C Spoofing Vulnerability | 0,4% | — |
| CVE-2026-58286 | HIGH 8.1 | microsoft edge_chromium Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2026-58282 | HIGH 8.1 | microsoft edge_chromium Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0,4% | — |