imPC@ndo EN

Vulnerabilità Microsoft

15.272 CVE

CVE-2010-0232
Sfruttata Alta 7.8

The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32…

microsoft windows_2000 · microsoft windows_7 · microsoft windows_xp
0.29EPSS
CVE-2017-0149
Sfruttata Alta 8.8

Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from tho…

microsoft internet_explorer
0.29EPSS
CVE-2022-37969
Sfruttata Alta 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 11
0.28EPSS
CVE-2024-38193
Sfruttata Alta 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.28EPSS
CVE-2018-8581
Ransomware Alta 7.4

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.

microsoft exchange_server
0.27EPSS
CVE-2021-36948
Sfruttata Alta 7.8

Windows Update Medic Service Elevation of Privilege Vulnerability

microsoft windows_10_1809 · microsoft windows_10_1909 · microsoft windows_10_2004 · microsoft windows_10_20h2 · e altri 4
0.27EPSS
CVE-2014-2817
Sfruttata Alta 8.8

Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."

microsoft internet_explorer
0.26EPSS
CVE-2016-3351
Ransomware Media 6.5

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

microsoft edge · microsoft internet_explorer
0.26EPSS
CVE-2023-36802
Sfruttata Alta 7.8

Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_21h2 · e altri 3
0.26EPSS
CVE-2026-21510
Sfruttata Alta 8.8

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · e altri 9
0.26EPSS
CVE-2024-49138
Sfruttata Alta 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.25EPSS
CVE-2024-35250
Sfruttata Alta 7.8

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 10
0.25EPSS
CVE-2022-41128
Sfruttata Alta 8.8

Windows Scripting Languages Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 12
0.25EPSS
CVE-2016-0040
Sfruttata Alta 7.8

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.25EPSS
CVE-2018-8653
Sfruttata Alta 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer …

microsoft internet_explorer
0.24EPSS
CVE-2020-1380
Sfruttata Alta 7.8

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current u…

microsoft internet_explorer
0.24EPSS
CVE-2016-3298
Sfruttata Media 6.5

Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Internet Explo…

microsoft internet_explorer · microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.23EPSS
CVE-2026-32201
Sfruttata Media 6.5

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

microsoft sharepoint_server
0.23EPSS
CVE-2025-14174
Sfruttata Alta 8.8

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

apple ipados · apple iphone_os · apple macos · apple safari · e altri 5
0.23EPSS
CVE-2026-56164
Sfruttata Media 5.3

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

microsoft sharepoint_server
0.22EPSS
CVE-2018-8639
Ransomware Alta 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 20…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 9
0.22EPSS
CVE-2023-29360
Sfruttata Alta 8.4

Microsoft Streaming Service Elevation of Privilege Vulnerability

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · e altri 5
0.22EPSS
CVE-2016-0162
Sfruttata Media 4.3

Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability."

microsoft internet_explorer
0.22EPSS
CVE-2019-1297
Sfruttata Alta 8.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.

microsoft excel · microsoft office · microsoft office_365_proplus
0.22EPSS
CVE-2019-0903
Sfruttata Alta 8.8

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 12
0.22EPSS