56.571 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.454 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-1999-0253 | HIGH 7.5 | microsoft internet_information_server IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. | 8,0% | — |
| CVE-2023-23410 | HIGH 7.8 | microsoft windows_10_1507 Windows HTTP.sys Elevation of Privilege Vulnerability | 8,0% | — |
| CVE-2006-1511 | MED 5.1 | microsoft .net_framework Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name. | 7,9% | — |
| CVE-2017-0242 | MED 5.5 | microsoft windows_7 An information disclosure vulnerability exists in the way some ActiveX objects are instantiated, aka "Microsoft ActiveX Information Disclosure Vulnerability." | 7,9% | — |
| CVE-2020-0847 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. | 7,9% | — |
| CVE-2016-3391 | MED 5.3 | microsoft edge Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow context-dependent attackers to discover credentials by leveraging access to a memory dump, aka "Microsoft Browser Information Disclosure Vulnerability." | 7,9% | — |
| CVE-2017-11845 | HIGH 7.5 | microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how Microsoft Edge handles objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". | 7,9% | — |
| CVE-2017-11788 | HIGH 7.5 | microsoft windows_10 Windows Search in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows server, version 1709 allows an unauthenticated attacker to remo | 7,9% | — |
| CVE-2019-0561 | MED 5.5 | microsoft office An information disclosure vulnerability exists when Microsoft Word macro buttons are used improperly, aka "Microsoft Word Information Disclosure Vulnerability." This affects Microsoft Word, Office 365 ProPlus, Microsoft Office, Word. | 7,9% | — |
| CVE-2017-11901 | HIGH 7.5 | microsoft internet_explorer Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the curren | 7,9% | — |
| CVE-2017-11862 | HIGH 7.5 | microsoft chakracore ChakraCore and Microsoft Edge in Windows 10 1709 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerabil | 7,9% | — |
| CVE-2018-0808 | HIGH 7.5 | microsoft asp.net_core ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how ASP.NET web applications handle web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0784. | 7,9% | — |
| CVE-2002-0700 | HIGH 7.5 | microsoft content_management_server Buffer overflow in a system function that performs user authentication for Microsoft Content Management Server (MCMS) 2001 allows attackers to execute code in the Local System context by authenticating to a web page that calls the function, aka "Unchecked Buff | 7,9% | — |
| CVE-2000-1147 | MED 4.6 | microsoft internet_information_server Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the "LANGUAGE" argument in a script tag. | 7,9% | — |
| CVE-2017-0129 | HIGH 7.5 | microsoft lync_for_mac Microsoft Lync for Mac 2011 fails to properly validate certificates, allowing remote attackers to alter server-client communications, aka "Microsoft Lync for Mac Certificate Validation Vulnerability." | 7,9% | — |
| CVE-2019-0688 | HIGH 7.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, aka 'Windows TCP/IP Information Disclosure Vulnerability'. | 7,9% | — |
| CVE-2020-0812 | HIGH 7.5 | microsoft chakracore A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based)L, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0811. | 7,9% | — |
| CVE-2023-21710 | HIGH 7.2 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 7,9% | — |
| CVE-2018-8351 | MED 6.5 | microsoft edge An information disclosure vulnerability exists when affected Microsoft browsers improperly allow cross-frame interaction, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10. | 7,9% | — |
| CVE-2019-0779 | HIGH 7.5 | microsoft edge A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'. | 7,9% | — |
| CVE-1999-0387 | HIGH 7.8 | microsoft windows_95 A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords. | 7,9% | — |
| CVE-2021-21124 | CRIT 9.6 | google chrome Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | 7,9% | — |
| CVE-2008-5912 | LOW 2.1 | microsoft internet_explorer An unspecified function in the JavaScript implementation in Microsoft Internet Explorer creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoof | 7,8% | — |
| CVE-2023-36731 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 7,8% | — |
| CVE-2025-49724 | HIGH 8.8 | microsoft windows_10_1809 Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network. | 7,8% | — |