56.950 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.479 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2025-49705 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2025-49700 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2024-43511 | HIGH 7.0 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2023-21725 | MED 6.3 | microsoft windows_malicious_software_removal_tool Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2026-63525 | HIGH 7.8 | microsoft 365_apps Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0,4% | — |
| CVE-2026-58613 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-21264 | CRIT 9.3 | microsoft account Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2025-59260 | MED 5.5 | microsoft windows_server_2016 Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2025-29841 | HIGH 7.0 | microsoft windows_10_21h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-70325 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-70323 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-70322 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-70320 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-70319 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-70316 | MED 5.5 | microsoft 365_apps Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-70315 | MED 5.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-50475 | MED 5.5 | microsoft windows_10_1607 Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally. | 0,4% | — |
| CVE-2026-45500 | MED 6.1 | microsoft exchange_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 0,4% | — |
| CVE-2025-59511 | HIGH 7.8 | microsoft windows_10_1809 External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-54112 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-54111 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-54099 | HIGH 7.0 | microsoft windows_10_1507 Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-53802 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2025-49659 | HIGH 7.8 | microsoft windows_10_1507 Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally. | 0,4% | — |
| CVE-2026-55012 | HIGH 7.8 | microsoft malware_protection_engine Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally. | 0,4% | — |