Vulnerabilidades en microsoft
9312 resultadosAnálisis Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2024-49085HIGHWindows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityEPSS 1.6%CVE-2020-0663—An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attEPSS 1.6%CVE-2024-49086HIGHWindows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityEPSS 1.6%CVE-2022-23261MEDIUMMicrosoft Edge (Chromium-based) Tampering VulnerabilityEPSS 1.6%CVE-2019-1134MEDIUMA cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requesEPSS 1.6%CVE-2019-0830MEDIUMA cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requesEPSS 1.6%CVE-2019-0831MEDIUMA cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requesEPSS 1.6%CVE-2019-0996—Azure DevOps Server Spoofing VulnerabilityEPSS 1.6%CVE-2022-41127HIGHMicrosoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution VulnerabilityEPSS 1.6%CVE-2021-28478HIGHMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 1.6%CVE-2024-49082MEDIUMWindows File Explorer Information Disclosure VulnerabilityEPSS 1.6%CVE-2023-23388HIGHWindows Bluetooth Driver Elevation of Privilege VulnerabilityEPSS 1.6%CVE-2020-0917—An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'WindowEPSS 1.6%CVE-2022-35794HIGHWindows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityEPSS 1.6%CVE-2025-21364HIGHMicrosoft Excel Security Feature Bypass VulnerabilityEPSS 1.6%CVE-2020-1326—A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOpsEPSS 1.6%CVE-2020-1454MEDIUMThis vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.EPSS 1.6%CVE-2025-47172HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 1.6%CVE-2023-35622HIGHWindows DNS Spoofing VulnerabilityEPSS 1.6%CVE-2025-32725HIGHDHCP Server Service Denial of Service VulnerabilityEPSS 1.6%