56.571 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.454 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2004-2011 | LOW 2.6 | microsoft internet_explorer msxml3.dll in Internet Explorer 6.0.2600.0 allows remote attackers to cause a denial of service (crash) via a single & (ampersand) in a <Ref href> link, which triggers a parsing error, possibly due to missing portions of the URI. | 7,4% | — |
| CVE-2000-0400 | HIGH 7.5 | microsoft internet_explorer The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an email message or news post. | 7,4% | — |
| CVE-2019-1371 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'. | 7,4% | — |
| CVE-2001-0003 | MED 5.0 | microsoft office Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the | 7,4% | — |
| CVE-2017-0258 | MED 4.7 | microsoft windows_10 The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows authenticated attackers to obtain sensitive infor | 7,4% | — |
| CVE-2001-0879 | MED 5.0 | microsoft sql_server Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service. | 7,4% | — |
| CVE-1999-0723 | HIGH 7.1 | microsoft windows_2000 The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input. | 7,4% | — |
| CVE-2021-26896 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability | 7,4% | — |
| CVE-2019-0741 | HIGH 7.5 | microsoft java_software_development_kit An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information, aka 'Azure IoT Java SDK Information Disclosure Vulnerability'. | 7,4% | — |
| CVE-2022-38051 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 7,3% | — |
| CVE-2022-38050 | HIGH 7.8 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 7,3% | — |
| CVE-2020-1493 | MED 5.5 | microsoft 365_apps An information disclosure vulnerability exists when attaching files to Outlook messages. This vulnerability could potentially allow users to share attached files such that they are accessible by anonymous users where they should be restricted to specific users | 7,3% | — |
| CVE-2005-1207 | HIGH 7.2 | microsoft windows_2003_server Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters. | 7,3% | — |
| CVE-2021-1645 | MED 5.0 | microsoft windows_10 Windows Docker Information Disclosure Vulnerability | 7,3% | — |
| CVE-2021-26895 | CRIT 9.8 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 7,3% | — |
| CVE-2021-26894 | CRIT 9.8 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 7,3% | — |
| CVE-2018-8416 | MED 6.5 | microsoft asp.net_core A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1. | 7,3% | — |
| CVE-2026-20959 | MED 4.6 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 7,2% | — |
| CVE-2017-11872 | MED 6.5 | microsoft edge Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to force the browser to send data that would otherwise be restricted to a destination website of the attacker's choice, due to how Microsoft Edge handles redirect req | 7,2% | — |
| CVE-2017-0276 | MED 5.9 | microsoft windows_10 Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, an | 7,2% | — |
| CVE-2017-0270 | MED 5.9 | microsoft windows_10 Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, an | 7,2% | — |
| CVE-2017-0268 | MED 5.9 | microsoft windows_10 Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, an | 7,2% | — |
| CVE-2023-36391 | HIGH 7.8 | microsoft windows_11_23h2 Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | 7,2% | — |
| CVE-2019-1332 | MED 6.1 | microsoft power_bi_report_server A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'. | 7,2% | — |
| CVE-2018-0741 | MED 5.3 | microsoft windows_7 The Color Management Module (Icm32.dll) in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Microsoft Color Management Information Disclosure Vulnerability". | 7,2% | — |