Vulnerabilidades em microsoft

10.822 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2020-0891MEDIUMThis vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.EPSS 1.5%CVE-2022-21839MEDIUMWindows Event Tracing Discretionary Access Control List Denial of Service VulnerabilityEPSS 1.5%CVE-2020-1377HIGHWindows Registry Elevation of Privilege VulnerabilityEPSS 1.5%CVE-2022-21891HIGHMicrosoft Dynamics 365 (on-premises) Spoofing VulnerabilityEPSS 1.5%CVE-2024-26227HIGHWindows DNS Server Remote Code Execution VulnerabilityEPSS 1.5%CVE-2024-26231HIGHWindows DNS Server Remote Code Execution VulnerabilityEPSS 1.5%CVE-2025-21380HIGHAzure Marketplace SaaS Resources Information Disclosure VulnerabilityEPSS 1.5%CVE-2023-36873HIGH.NET Framework Spoofing VulnerabilityEPSS 1.5%CVE-2022-37978HIGHWindows Active Directory Certificate Services Security Feature BypassEPSS 1.5%CVE-2023-24881MEDIUMMicrosoft Teams Information Disclosure VulnerabilityEPSS 1.5%CVE-2023-28312MEDIUMAzure Machine Learning Information Disclosure VulnerabilityEPSS 1.5%CVE-2018-8652—A Cross-site Scripting (XSS) vulnerability exists when Windows Azure Pack does not properly sanitize user-provided input, aka "Windows AzureEPSS 1.5%CVE-2025-53716MEDIUMWindows Local Security Authority Subsystem Service (LSASS) Denial of Service VulnerabilityEPSS 1.5%CVE-2025-50172MEDIUMDirectX Graphics Kernel Denial of Service VulnerabilityEPSS 1.5%CVE-2024-21313MEDIUMWindows TCP/IP Information Disclosure VulnerabilityEPSS 1.5%CVE-2025-53809MEDIUMWindows Local Security Authority Subsystem Service (LSASS) Denial of Service VulnerabilityEPSS 1.5%CVE-2022-22040HIGHInternet Information Services Dynamic Compression Module Denial of Service VulnerabilityEPSS 1.5%CVE-2020-0642—An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EPSS 1.5%CVE-2025-21283MEDIUMMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 1.5%CVE-2022-30203HIGHWindows Boot Manager Security Feature Bypass VulnerabilityEPSS 1.5%