imPC@ndo EN

Vulnerabilità Microsoft

15.257 CVE

CVE-2023-44487
Sfruttata Alta 7.5

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

akka http_server · amazon opensearch_data_prepper · apache apisix · apache solr · e altri 161
1.00EPSS
CVE-2015-1635
Sfruttata Critica 9.8

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_server_2008 · e altri 1
1.00EPSS
CVE-2021-34473
Ransomware Critica 9.1

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2021-26855
Ransomware Critica 9.1

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2019-0708
Ransomware Critica 9.8

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code …

huawei agile_controller-campus_firmware · huawei bh620_v2_firmware · huawei bh621_v2_firmware · huawei bh622_v2_firmware · e altri 63
1.00EPSS
CVE-2021-34523
Ransomware Critica 9.0

Microsoft Exchange Server Elevation of Privilege Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2025-53770
Ransomware Critica 9.8

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a co…

microsoft sharepoint_server
1.00EPSS
CVE-2022-41082
Ransomware Alta 8.0

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2012-0158
Sfruttata Alta 8.8

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2…

microsoft biztalk_server · microsoft commerce_server · microsoft commerce_server_2009 · microsoft office · e altri 6
1.00EPSS
CVE-2020-0688
Ransomware Alta 8.8

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.

microsoft exchange_server
1.00EPSS
CVE-2022-41040
Ransomware Alta 8.8

Microsoft Exchange Server Elevation of Privilege Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2021-27065
Ransomware Alta 7.8

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2017-11882
Ransomware Alta 7.8

Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memo…

microsoft office
1.00EPSS
CVE-2025-59287
Sfruttata Critica 9.8

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019 · microsoft windows_server_2022 · e altri 2
1.00EPSS
CVE-2021-38647
Ransomware Critica 9.8

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

microsoft azure_automation_state_configuration · microsoft azure_automation_update_management · microsoft azure_diagnostics_\(lad\) · microsoft azure_security_center · e altri 6
1.00EPSS
CVE-2017-0199
Ransomware Alta 7.8

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, ak…

microsoft office · microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_server_2012 · e altri 2
1.00EPSS
CVE-2025-49704
Ransomware Alta 8.8

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

microsoft sharepoint_server
1.00EPSS
CVE-2025-49706
Ransomware Media 6.5

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

microsoft sharepoint_enterprise_server · microsoft sharepoint_server
1.00EPSS
CVE-2019-0604
Ransomware Critica 9.8

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.

microsoft sharepoint_enterprise_server · microsoft sharepoint_foundation · microsoft sharepoint_server
1.00EPSS
CVE-2017-7269
Sfruttata Critica 9.8

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PRO…

microsoft internet_information_services
1.00EPSS
CVE-2020-0796
Ransomware Critica 10.0

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

microsoft windows_10_1903 · microsoft windows_10_1909 · microsoft windows_server_1903 · microsoft windows_server_1909
1.00EPSS
CVE-2021-34527
Ransomware Alta 8.8

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could the…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 11
1.00EPSS
CVE-2021-31207
Ransomware Media 6.6

Microsoft Exchange Server Security Feature Bypass Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2023-4863
Sfruttata Alta 8.8

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

bandisoft honeyview · bentley seequent_leapfrog · debian debian_linux · fedoraproject fedora · e altri 8
1.00EPSS
CVE-2017-0147
Ransomware Alta 7.5

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sen…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_7 · e altri 14
1.00EPSS