58.476 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
16.464 CVE
| Identificativo | Gravità, ordinato dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2026-85889 | CRIT 10.0 | microsoft azure_ai_foundry Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-83944 | CRIT 10.0 | microsoft azure_logic_apps Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-70200 | CRIT 10.0 | microsoft azure_logic_apps Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-69865 | CRIT 10.0 | microsoft azure_container_registry Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-69843 | CRIT 10.0 | microsoft fabric Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-69836 | CRIT 10.0 | microsoft entra_id Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. | 1,5% | — |
| CVE-2026-69555 | CRIT 10.0 | microsoft azure_arc Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-69502 | CRIT 10.0 | microsoft azure_sql_database Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-69399 | CRIT 10.0 | microsoft azure_arc Azure Arc Elevation of Privilege Vulnerability | 0,9% | — |
| CVE-2026-66803 | CRIT 10.0 | microsoft azure_cosmos_db Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. | 0,9% | — |
| CVE-2026-65816 | CRIT 10.0 | microsoft azure_web_apps Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | 1,0% | — |
| CVE-2026-65801 | CRIT 10.0 | microsoft exchange_online Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-65770 | CRIT 10.0 | microsoft azure_managed_instance_for_apache_cassandra Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. | 1,1% | — |
| CVE-2026-65667 | CRIT 10.0 | microsoft teams Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-63508 | CRIT 10.0 | microsoft planetary_computer Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. | 0,8% | — |
| CVE-2026-62825 | CRIT 10.0 | microsoft azure_key_vault Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-58630 | CRIT 10.0 | microsoft azure_app_service_for_linux Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-58275 | CRIT 10.0 | microsoft azure_dns Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-57106 | CRIT 10.0 | microsoft purview_data_governance Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-56191 | CRIT 10.0 | microsoft exchange_online Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. | 0,9% | — |
| CVE-2026-56163 | CRIT 10.0 | microsoft azure_kubernetes_service Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-56162 | CRIT 10.0 | microsoft azure_sql_database Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-48567 | CRIT 10.0 | microsoft azure_horizondb Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-47280 | CRIT 10.0 | microsoft azure_resource_manager Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |
| CVE-2026-45480 | CRIT 10.0 | microsoft azure_active_directory Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. | 0,9% | — |