56.959 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.479 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-50333 | HIGH 7.8 | microsoft windows_10_1607 Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-50311 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Server allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-49170 | HIGH 7.8 | microsoft windows_10_1809 Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-48581 | HIGH 7.8 | microsoft surface_go_2_1901_firmware Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-40409 | HIGH 7.8 | microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 0,3% | — |
| CVE-2026-40408 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-34333 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-27919 | HIGH 7.8 | microsoft windows_10_1607 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-27915 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-27907 | HIGH 7.8 | microsoft windows_11_23h2 Integer underflow (wrap or wraparound) in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-26180 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-26163 | HIGH 7.8 | microsoft windows_10_1607 Double free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-26162 | HIGH 7.8 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-26161 | HIGH 7.8 | microsoft windows_10_1809 Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-25167 | HIGH 7.4 | microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-53768 | HIGH 7.8 | microsoft windows_10_1507 Use after free in Xbox allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-53150 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-29973 | HIGH 7.0 | microsoft azure_file_sync Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-32161 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthorized attacker to execute code over an adjacent network. | 0,3% | — |
| CVE-2026-23656 | MED 5.9 | microsoft windows_app Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network. | 0,3% | — |
| CVE-2026-69278 | HIGH 7.8 | microsoft visual_studio_code Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2026-58650 | HIGH 7.8 | microsoft visual_studio_code Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0,3% | — |
| CVE-2026-50650 | HIGH 7.8 | microsoft .net Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2025-59191 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. | 0,3% | — |
| CVE-2026-50375 | MED 6.3 | microsoft windows_10_1809 Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally. | 0,3% | — |