56.959 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.479 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-62772 | HIGH 7.8 | microsoft windows_11_26h1 Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-62770 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-62758 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-62755 | HIGH 7.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-62736 | HIGH 7.8 | microsoft windows_11_23h2 Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-62733 | HIGH 7.8 | microsoft windows_10_1607 Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-42838 | MED 5.4 | microsoft edge_chromium Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. | 0,2% | — |
| CVE-2026-27920 | HIGH 7.8 | microsoft windows_10_1607 Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-27916 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-26184 | HIGH 7.8 | microsoft windows_10_1809 Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2025-49728 | MED 4.0 | microsoft pc_manager Cleartext storage of sensitive information in Microsoft PC Manager allows an unauthorized attacker to bypass a security feature locally. | 0,2% | — |
| CVE-2026-49161 | HIGH 7.8 | microsoft pc_manager Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally. | 0,2% | — |
| CVE-2026-0385 | MED 5.0 | microsoft edge_chromium Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability | 0,2% | — |
| CVE-2026-61349 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2025-59189 | HIGH 7.4 | microsoft windows_11_24h2 Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2025-62219 | HIGH 7.0 | microsoft windows_10_1607 Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2025-62218 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-50325 | HIGH 7.0 | microsoft windows_10_1607 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-50297 | HIGH 7.0 | microsoft windows_10_1607 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-49805 | HIGH 7.0 | microsoft windows_10_1607 Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2025-58725 | HIGH 7.0 | microsoft windows_10_1507 Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally. | 0,2% | — |
| CVE-2026-70339 | MED 5.4 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0,2% | — |
| CVE-2026-65804 | MED 6.1 | microsoft edge_chromium Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0,2% | — |
| CVE-2026-62828 | MED 5.4 | microsoft edge Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network. | 0,2% | — |
| CVE-2026-58638 | MED 6.0 | microsoft windows_10_1809 Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. | 0,2% | — |