Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2022-30157HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 7.0%CVE-2021-26893CRITICALWindows DNS Server Remote Code Execution VulnerabilityEPSS 7.0%CVE-2021-38665HIGHRemote Desktop Protocol Client Information Disclosure VulnerabilityEPSS 7.0%CVE-2019-0786—An elevation of privilege vulnerability exists in the Microsoft Server Message Block (SMB) Server when an attacker with valid credentials atEPSS 7.0%CVE-2025-21204HIGHWindows Process Activation Elevation of Privilege VulnerabilityEPSS 7.0%CVE-2019-0961—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 7.0%CVE-2019-0882—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 7.0%CVE-2019-0774—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 7.0%CVE-2020-1238—A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory CoEPSS 7.0%CVE-2024-38052HIGHKernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityEPSS 7.0%CVE-2020-0690—An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege VulnerEPSS 7.0%CVE-2019-0815—A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service VulnerabilitEPSS 7.0%CVE-2018-8278—A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." TEPSS 6.9%CVE-2018-8595—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows EPSS 6.9%CVE-2019-1361—An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft GraphiEPSS 6.9%CVE-2019-1064HIGHWindows Elevation of Privilege VulnerabilityEPSS 6.9%KEVCVE-2024-30034MEDIUMWindows Cloud Files Mini Filter Driver Information Disclosure VulnerabilityEPSS 6.9%CVE-2020-1284—A denial of service vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests,EPSS 6.9%CVE-2018-8383—A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content, aka "Microsoft Edge Spoofing Vulnerability." This EPSS 6.8%CVE-2020-1022—A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution VuEPSS 6.8%