Vulnerabilidades em microsoft
10.822 resultadosAnálise Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2019-0963MEDIUMA cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requesEPSS 1.6%CVE-2024-43533HIGHRemote Desktop Client Remote Code Execution VulnerabilityEPSS 1.6%CVE-2019-0951—A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SEPSS 1.6%CVE-2023-36718HIGHMicrosoft Virtual Trusted Platform Module Remote Code Execution VulnerabilityEPSS 1.6%CVE-2021-41357HIGHWin32k Elevation of Privilege VulnerabilityEPSS 1.6%KEVCVE-2024-35267HIGHAzure DevOps Server Spoofing VulnerabilityEPSS 1.6%CVE-2024-35266HIGHAzure DevOps Server Spoofing VulnerabilityEPSS 1.6%CVE-2021-40450HIGHWin32k Elevation of Privilege VulnerabilityEPSS 1.6%KEVCVE-2018-0964—An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authEPSS 1.6%CVE-2025-21178HIGHVisual Studio Remote Code Execution VulnerabilityEPSS 1.6%CVE-2018-0957—An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authEPSS 1.6%CVE-2019-1137—A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request EPSS 1.6%CVE-2018-8650MEDIUMA cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requesEPSS 1.6%CVE-2026-21514HIGHMicrosoft Word Security Feature Bypass VulnerabilityEPSS 1.6%KEVCVE-2020-1340—A spoofing vulnerability exists when the NuGetGallery does not properly sanitize input on package metadata values, aka 'NuGetGallery SpoofinEPSS 1.6%CVE-2020-17063MEDIUMMicrosoft Office Online Spoofing VulnerabilityEPSS 1.6%CVE-2022-23258MEDIUMMicrosoft Edge for Android Spoofing VulnerabilityEPSS 1.6%CVE-2024-21353HIGHMicrosoft WDAC ODBC Driver Remote Code Execution VulnerabilityEPSS 1.6%CVE-2025-24056HIGHWindows Telephony Service Remote Code Execution VulnerabilityEPSS 1.6%CVE-2022-23261MEDIUMMicrosoft Edge (Chromium-based) Tampering VulnerabilityEPSS 1.6%