EN
56.571 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia

Vulnerabilità Microsoft

15.454 CVE

Vulnerabilità Microsoft
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-1999-0253 HIGH 7.5 microsoft internet_information_server IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. 8,0%
CVE-2023-23410 HIGH 7.8 microsoft windows_10_1507 Windows HTTP.sys Elevation of Privilege Vulnerability 8,0%
CVE-2006-1511 MED 5.1 microsoft .net_framework Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name. 7,9%
CVE-2017-0242 MED 5.5 microsoft windows_7 An information disclosure vulnerability exists in the way some ActiveX objects are instantiated, aka "Microsoft ActiveX Information Disclosure Vulnerability." 7,9%
CVE-2020-0847 HIGH 7.5 microsoft internet_explorer A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. 7,9%
CVE-2016-3391 MED 5.3 microsoft edge Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow context-dependent attackers to discover credentials by leveraging access to a memory dump, aka "Microsoft Browser Information Disclosure Vulnerability." 7,9%
CVE-2017-11845 HIGH 7.5 microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how Microsoft Edge handles objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". 7,9%
CVE-2017-11788 HIGH 7.5 microsoft windows_10 Windows Search in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows server, version 1709 allows an unauthenticated attacker to remo 7,9%
CVE-2019-0561 MED 5.5 microsoft office An information disclosure vulnerability exists when Microsoft Word macro buttons are used improperly, aka "Microsoft Word Information Disclosure Vulnerability." This affects Microsoft Word, Office 365 ProPlus, Microsoft Office, Word. 7,9%
CVE-2017-11901 HIGH 7.5 microsoft internet_explorer Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the curren 7,9%
CVE-2017-11862 HIGH 7.5 microsoft chakracore ChakraCore and Microsoft Edge in Windows 10 1709 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerabil 7,9%
CVE-2018-0808 HIGH 7.5 microsoft asp.net_core ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how ASP.NET web applications handle web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0784. 7,9%
CVE-2002-0700 HIGH 7.5 microsoft content_management_server Buffer overflow in a system function that performs user authentication for Microsoft Content Management Server (MCMS) 2001 allows attackers to execute code in the Local System context by authenticating to a web page that calls the function, aka "Unchecked Buff 7,9%
CVE-2000-1147 MED 4.6 microsoft internet_information_server Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the "LANGUAGE" argument in a script tag. 7,9%
CVE-2017-0129 HIGH 7.5 microsoft lync_for_mac Microsoft Lync for Mac 2011 fails to properly validate certificates, allowing remote attackers to alter server-client communications, aka "Microsoft Lync for Mac Certificate Validation Vulnerability." 7,9%
CVE-2019-0688 HIGH 7.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, aka 'Windows TCP/IP Information Disclosure Vulnerability'. 7,9%
CVE-2020-0812 HIGH 7.5 microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based)L, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0811. 7,9%
CVE-2023-21710 HIGH 7.2 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 7,9%
CVE-2018-8351 MED 6.5 microsoft edge An information disclosure vulnerability exists when affected Microsoft browsers improperly allow cross-frame interaction, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10. 7,9%
CVE-2019-0779 HIGH 7.5 microsoft edge A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'. 7,9%
CVE-1999-0387 HIGH 7.8 microsoft windows_95 A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords. 7,9%
CVE-2021-21124 CRIT 9.6 google chrome Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. 7,9%
CVE-2008-5912 LOW 2.1 microsoft internet_explorer An unspecified function in the JavaScript implementation in Microsoft Internet Explorer creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoof 7,8%
CVE-2023-36731 HIGH 7.8 microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability 7,8%
CVE-2025-49724 HIGH 8.8 microsoft windows_10_1809 Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network. 7,8%