Vulnerabilidades em microsoft

10.822 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2023-21553HIGHAzure DevOps Server Remote Code Execution VulnerabilityEPSS 1.4%CVE-2024-20655MEDIUMMicrosoft Online Certificate Status Protocol (OCSP) Remote Code Execution VulnerabilityEPSS 1.4%CVE-2025-25005MEDIUMMicrosoft Exchange Server Tampering VulnerabilityEPSS 1.4%CVE-2024-38029HIGHMicrosoft OpenSSH for Windows Remote Code Execution VulnerabilityEPSS 1.4%CVE-2023-35316MEDIUMRemote Procedure Call Runtime Information Disclosure VulnerabilityEPSS 1.4%CVE-2025-32701HIGHWindows Common Log File System Driver Elevation of Privilege VulnerabilityEPSS 1.4%KEVCVE-2019-0816—A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init,EPSS 1.4%CVE-2020-17094MEDIUMWindows Error Reporting Information Disclosure VulnerabilityEPSS 1.4%CVE-2020-1148—A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SEPSS 1.4%CVE-2020-17147HIGHDynamics CRM Webclient Cross-site Scripting VulnerabilityEPSS 1.4%CVE-2020-17098MEDIUMWindows GDI+ Information Disclosure VulnerabilityEPSS 1.4%CVE-2022-44702HIGHWindows Terminal Remote Code Execution VulnerabilityEPSS 1.4%CVE-2021-36949HIGHMicrosoft Azure Active Directory Connect Authentication Bypass VulnerabilityEPSS 1.4%CVE-2020-16970HIGHAzure Sphere Unsigned Code Execution VulnerabilityEPSS 1.4%CVE-2023-24876HIGHMicrosoft PostScript and PCL6 Class Printer Driver Remote Code Execution VulnerabilityEPSS 1.4%CVE-2019-1409—An information disclosure vulnerability exists when the Windows Remote Procedure Call (RPC) runtime improperly initializes objects in memoryEPSS 1.4%CVE-2023-29354MEDIUMMicrosoft Edge (Chromium-based) Security Feature Bypass VulnerabilityEPSS 1.4%CVE-2023-36043MEDIUMOpen Management Infrastructure Information Disclosure VulnerabilityEPSS 1.4%CVE-2023-36882HIGHMicrosoft WDAC OLE DB provider for SQL Server Remote Code Execution VulnerabilityEPSS 1.4%CVE-2025-21291HIGHWindows Direct Show Remote Code Execution VulnerabilityEPSS 1.4%