56.932 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.479 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-54115 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2022-26808 | HIGH 7.0 | microsoft windows_10 Windows File Explorer Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2026-58643 | MED 6.1 | microsoft windows_admin_center Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2026-58524 | MED 5.4 | microsoft edge_chromium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2026-58298 | HIGH 7.2 | microsoft edge_chromium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2026-45655 | MED 5.3 | microsoft windows_10_1607 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0,4% | — |
| CVE-2025-55321 | CRIT 9.3 | microsoft azure_monitor Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2024-38208 | MED 6.1 | microsoft edge Microsoft Edge for Android Spoofing Vulnerability | 0,4% | — |
| CVE-2024-38156 | MED 6.1 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0,4% | — |
| CVE-2026-69306 | HIGH 8.2 | microsoft visual_studio_code Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0,4% | — |
| CVE-2026-64922 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2026-64916 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2026-64902 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2026-64897 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2026-50428 | HIGH 7.1 | microsoft windows_11_26h1 Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-49707 | HIGH 7.9 | microsoft dcadsv5-series_azure_vm_firmware Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally. | 0,4% | — |
| CVE-2026-45636 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-32188 | HIGH 7.1 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-26156 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-23657 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-60718 | HIGH 7.8 | microsoft windows_11_24h2 Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2023-35299 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2022-29113 | HIGH 7.8 | microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2026-54999 | HIGH 8.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network. | 0,4% | — |
| CVE-2025-54103 | HIGH 7.4 | microsoft windows_10_21h2 Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally. | 0,4% | — |