56.959 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.479 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-33119 | MED 5.4 | microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0,3% | — |
| CVE-2023-24920 | MED 5.4 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0,3% | — |
| CVE-2026-33828 | HIGH 7.8 | microsoft windows_10_1607 Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-33841 | HIGH 7.8 | microsoft windows_10_21h2 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-21224 | HIGH 7.8 | microsoft azure_connected_machine_agent Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-49723 | HIGH 8.8 | microsoft windows_10_1809 Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally. | 0,3% | — |
| CVE-2026-45654 | HIGH 7.9 | microsoft windows_11_24h2 Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2026-20924 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-20918 | HIGH 7.8 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-20877 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-62459 | HIGH 8.3 | microsoft 365_defender_portal Microsoft Defender Portal Spoofing Vulnerability | 0,3% | — |
| CVE-2026-45501 | MED 6.5 | microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | 0,3% | — |
| CVE-2026-23660 | HIGH 7.8 | microsoft windows_admin_center Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-66806 | MED 5.5 | microsoft 365_apps Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-50451 | HIGH 7.1 | microsoft windows_10_1607 Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-45641 | HIGH 8.4 | microsoft windows_10_21h2 Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally. | 0,3% | — |
| CVE-2026-33098 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-32212 | MED 5.5 | microsoft windows_10_1607 Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. | 0,3% | — |
| CVE-2026-32168 | HIGH 7.8 | microsoft azure_monitor_agent Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-20831 | HIGH 7.8 | microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-20826 | HIGH 7.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-47991 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2022-41100 | HIGH 7.8 | microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 0,3% | — |
| CVE-2022-41045 | HIGH 7.8 | microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 0,3% | — |
| CVE-2026-54127 | HIGH 7.4 | microsoft windows_11_24h2 Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. | 0,3% | — |