56.560 CVE seguite
773 Sfruttate ora
181 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.453 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-44487 | HIGH 7.5 | akka http_server The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | 100,0% | |
| CVE-2021-34473 | CRIT 9.1 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 100,0% | |
| CVE-2021-26855 | CRIT 9.1 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 100,0% | |
| CVE-2019-0708 | CRIT 9.8 | ransomware huawei agile_controller-campus_firmware A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code | 100,0% | |
| CVE-2015-1635 | CRIT 9.8 | microsoft windows_7 HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability." | 100,0% | |
| CVE-2023-50387 | HIGH 7.5 | fedoraproject fedora Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when ther | 100,0% | — |
| CVE-2021-34523 | CRIT 9.0 | ransomware microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 100,0% | |
| CVE-2025-53770 | CRIT 9.8 | ransomware microsoft sharepoint_server Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a co | 100,0% | |
| CVE-2022-41082 | HIGH 8.0 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 100,0% | |
| CVE-2012-0158 | HIGH 8.8 | microsoft biztalk_server The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2 | 100,0% | |
| CVE-2020-0688 | HIGH 8.8 | ransomware microsoft exchange_server A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'. | 100,0% | |
| CVE-2022-41040 | HIGH 8.8 | ransomware microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 100,0% | |
| CVE-2021-27065 | HIGH 7.8 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 99,9% | |
| CVE-2017-11882 | HIGH 7.8 | ransomware microsoft office Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memo | 99,9% | |
| CVE-2025-59287 | CRIT 9.8 | microsoft windows_server_2012 Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | 99,9% | |
| CVE-2021-38647 | CRIT 9.8 | ransomware microsoft azure_automation_state_configuration Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | 99,9% | |
| CVE-2017-0199 | HIGH 7.8 | ransomware microsoft office Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, ak | 99,9% | |
| CVE-2025-49704 | HIGH 8.8 | ransomware microsoft sharepoint_server Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 99,9% | |
| CVE-2025-53771 | MED 6.5 | microsoft sharepoint_server Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 99,9% | — |
| CVE-2025-49706 | MED 6.5 | ransomware microsoft sharepoint_enterprise_server Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 99,9% | |
| CVE-2015-4000 | LOW 3.7 | apple iphone_os The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello wi | 99,9% | — |
| CVE-2019-0604 | CRIT 9.8 | ransomware microsoft sharepoint_enterprise_server A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594. | 99,8% | |
| CVE-2017-7269 | CRIT 9.8 | microsoft internet_information_services Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PRO | 99,8% | |
| CVE-2012-1459 | MED 4.3 | ahnlab v3_internet_security The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, | 99,8% | — |
| CVE-2020-0796 | CRIT 10.0 | ransomware microsoft windows_10_1903 A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'. | 99,8% |