Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2025-21385HIGHMicrosoft Purview Information Disclosure VulnerabilityEPSS 24.4%CVE-2018-8225—A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, EPSS 24.3%CVE-2026-21510HIGHWindows Shell Security Feature Bypass VulnerabilityEPSS 24.2%KEVCVE-2020-1380HIGHScripting Engine Memory Corruption VulnerabilityEPSS 24.2%KEVCVE-2022-21881HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 24.2%CVE-2024-26230HIGHWindows Telephony Server Elevation of Privilege VulnerabilityEPSS 24.1%CVE-2018-1030—A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka EPSS 24.1%CVE-2018-8176—A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka EPSS 24.1%CVE-2018-8154—A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, akEPSS 24.1%CVE-2023-38152MEDIUMDHCP Server Service Information Disclosure VulnerabilityEPSS 24.0%CVE-2019-1352—A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code EEPSS 24.0%CVE-2023-36005HIGHWindows Telephony Server Elevation of Privilege VulnerabilityEPSS 23.9%CVE-2022-35803HIGHWindows Common Log File System Driver Elevation of Privilege VulnerabilityEPSS 23.8%CVE-2024-30081HIGHWindows NTLM Spoofing VulnerabilityEPSS 23.8%CVE-2019-0724—An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege VulnerabiEPSS 23.8%CVE-2020-1400—A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 23.7%CVE-2025-29793HIGHMicrosoft SharePoint Remote Code Execution VulnerabilityEPSS 23.6%CVE-2019-1117—A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution VEPSS 23.6%CVE-2019-1118—A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution VEPSS 23.6%CVE-2020-1481—A remote code execution vulnerability exists in the ESLint extension for Visual Studio Code when it validates source code after opening a prEPSS 23.6%