56.932 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.479 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-62453 | MED 5.0 | microsoft visual_studio_code Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally. | 0,4% | — |
| CVE-2026-21251 | HIGH 7.8 | microsoft windows_server_2016 Use after free in Windows Cluster Client Failover allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-21246 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-21245 | HIGH 7.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-21239 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-21236 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-21232 | HIGH 7.8 | microsoft windows_11_23h2 Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-26636 | MED 5.5 | microsoft windows_11_24h2 Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2023-36565 | HIGH 7.0 | microsoft 365_copilot Microsoft Office Graphics Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2026-32181 | MED 5.5 | microsoft windows_10_21h2 Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally. | 0,4% | — |
| CVE-2026-26178 | HIGH 8.8 | microsoft windows_10_1607 Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-26109 | HIGH 8.4 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-62557 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-21522 | MED 6.7 | microsoft confcom Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-20962 | MED 4.4 | microsoft windows_10_1809 Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-60703 | HIGH 7.8 | microsoft windows_10_1607 Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-59201 | HIGH 7.8 | microsoft windows_10_1507 Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-56167 | HIGH 8.5 | microsoft azure_ai_search Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. | 0,4% | — |
| CVE-2026-20956 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-62216 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-62205 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-59292 | HIGH 8.2 | microsoft azure_compute_gallery External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-59291 | HIGH 8.2 | microsoft azure_compute_gallery External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-55317 | HIGH 7.8 | microsoft autoupdate Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-55245 | HIGH 7.8 | microsoft xbox_gaming_services Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally. | 0,4% | — |