Vulnerabilidades em microsoft

10.811 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2019-1091—An information disclosure vulnerability exists when Unistore.dll fails to properly handle objects in memory, aka 'Microsoft unistore.dll InfEPSS 2.0%CVE-2025-21268MEDIUMMapUrlToZone Security Feature Bypass VulnerabilityEPSS 2.0%CVE-2023-38156HIGHAzure HDInsight Apache Ambari JDBC Injection Elevation of Privilege VulnerabilityEPSS 2.0%CVE-2023-28241HIGHWindows Secure Socket Tunneling Protocol (SSTP) Denial of Service VulnerabilityEPSS 2.0%CVE-2023-24938MEDIUMWindows CryptoAPI Denial of Service VulnerabilityEPSS 2.0%CVE-2023-33129MEDIUMMicrosoft SharePoint Server Denial of Service VulnerabilityEPSS 2.0%CVE-2023-29369MEDIUMRemote Procedure Call Runtime Denial of Service VulnerabilityEPSS 2.0%CVE-2020-1482MEDIUMMicrosoft Office SharePoint XSS VulnerabilityEPSS 2.0%CVE-2023-21709CRITICALMicrosoft Exchange Server Elevation of Privilege VulnerabilityEPSS 2.0%CVE-2023-36891HIGHMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 2.0%CVE-2019-0874—A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOpsEPSS 2.0%CVE-2023-36892HIGHMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 2.0%CVE-2019-1266—A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'MicrosofEPSS 2.0%CVE-2023-29330HIGHMicrosoft Teams Remote Code Execution VulnerabilityEPSS 2.0%CVE-2024-49019HIGHActive Directory Certificate Services Elevation of Privilege VulnerabilityEPSS 2.0%CVE-2024-30090HIGHMicrosoft Streaming Service Elevation of Privilege VulnerabilityEPSS 2.0%CVE-2021-33754HIGHWindows DNS Server Remote Code Execution VulnerabilityEPSS 2.0%CVE-2021-43255MEDIUMMicrosoft Office Trust Center Spoofing VulnerabilityEPSS 2.0%CVE-2020-1595CRITICALMicrosoft SharePoint Remote Code Execution VulnerabilityEPSS 2.0%CVE-2022-35744CRITICALWindows Point-to-Point Protocol (PPP) Remote Code Execution VulnerabilityEPSS 2.0%