imPC@ndo IT

Microsoft vulnerabilities

15.347 CVE

CVE-2019-0841
Ransomware High 7.8

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-08…

microsoft windows_10_1703 · microsoft windows_10_1709 · microsoft windows_10_1803 · microsoft windows_10_1809 · and 2 more
0.41EPSS
CVE-2024-38178
Exploited High 7.5

Scripting Engine Memory Corruption Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 10 more
0.41EPSS
CVE-2020-1464
Exploited High 7.8

A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass secur…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · and 14 more
0.41EPSS
CVE-2023-29336
Exploited High 7.8

Win32k Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_server_2008 · microsoft windows_server_2012 · and 1 more
0.41EPSS
CVE-2021-34448
Exploited Medium 6.8

Scripting Engine Memory Corruption Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · and 10 more
0.40EPSS
CVE-2013-3660
Exploited High 7.8

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not proper…

microsoft windows_7 · microsoft windows_8 · microsoft windows_rt · microsoft windows_server_2003 · and 4 more
0.40EPSS
CVE-2021-1647
Exploited High 7.8

Microsoft Defender Remote Code Execution Vulnerability

microsoft security_essentials · microsoft system_center_endpoint_protection · microsoft windows_defender
0.39EPSS
CVE-2015-2502
Exploited High 8.8

Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.

microsoft internet_explorer
0.39EPSS
CVE-2015-2424
Exploited High 8.8

Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Off…

microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack · microsoft powerpoint · and 2 more
0.38EPSS
CVE-2023-4762
Exploited High 8.8

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

debian debian_linux · fedoraproject fedora · google chrome · microsoft edge_chromium
0.38EPSS
CVE-2016-0099
Ransomware High 7.8

The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows lo…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_7 · microsoft windows_8.1 · and 3 more
0.37EPSS
CVE-2020-17144
Exploited High 8.4

Microsoft Exchange Remote Code Execution Vulnerability

microsoft exchange_server
0.37EPSS
CVE-2015-2387
Exploited High 7.8

ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users …

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · and 5 more
0.35EPSS
CVE-2015-1770
Exploited High 8.8

Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerability."

microsoft office
0.35EPSS
CVE-2013-5065
Exploited High 7.8

NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.

microsoft windows_2003_server · microsoft windows_xp
0.35EPSS
CVE-2015-0071
Exploited Medium 6.5

Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."

microsoft internet_explorer
0.34EPSS
CVE-2021-42292
Exploited High 7.8

Microsoft Excel Security Feature Bypass Vulnerability

microsoft 365_apps · microsoft excel · microsoft office · microsoft office_long_term_servicing_channel
0.32EPSS
CVE-2022-4135
Exploited Critical 9.6

Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

google chrome · microsoft edge · microsoft edge_chromium
0.32EPSS
CVE-2011-2005
Exploited High 7.8

afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Dr…

microsoft windows_server_2003 · microsoft windows_xp
0.32EPSS
CVE-2026-20963
Exploited Critical 9.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

microsoft sharepoint_server
0.32EPSS
CVE-2025-26633
Ransomware High 7.0

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.30EPSS
CVE-2024-21351
Exploited High 7.6

Windows SmartScreen Security Feature Bypass Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 8 more
0.30EPSS
CVE-2020-0968
Exploited High 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0970.

microsoft internet_explorer
0.30EPSS
CVE-2019-1405
Ransomware High 7.8

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · and 11 more
0.30EPSS
CVE-2017-0222
Exploited High 8.8

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.

microsoft internet_explorer
0.30EPSS