56.571 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.454 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2019-0882 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0758, CVE-2019-0961. | 7,0% | — |
| CVE-2019-0774 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0614. | 7,0% | — |
| CVE-2020-1238 | HIGH 8.8 | microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1239. | 7,0% | — |
| CVE-2011-1974 | HIGH 7.2 | microsoft windows_2003_server NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "NDISTAPI | 7,0% | — |
| CVE-2025-33070 | HIGH 8.1 | microsoft windows_10_1507 Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network. | 7,0% | — |
| CVE-2017-0107 | MED 6.1 | microsoft sharepoint_foundation Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run cross-script in local security context, aka "Microsoft SharePoint XSS Vulnerability." | 7,0% | — |
| CVE-2006-6578 | HIGH 7.5 | microsoft internet_information_services Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows attackers to execute arbitrary commands via arguments to any .COM file that executes those arguments, as demonstrated u | 7,0% | — |
| CVE-2001-1450 | LOW 2.6 | microsoft internet_explorer Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./". | 7,0% | — |
| CVE-2001-0807 | LOW 2.6 | microsoft internet_explorer Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client's hard drive via a SCRIPT tag with a SRC value that points to the text file. | 7,0% | — |
| CVE-2024-38052 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | 7,0% | — |
| CVE-2020-0690 | CRIT 9.8 | microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. | 7,0% | — |
| CVE-2019-0815 | HIGH 7.5 | microsoft asp.net_core A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. | 7,0% | — |
| CVE-1999-0511 | CRIT 9.1 | microsoft windows_2000 IP forwarding is enabled on a machine which is not a router or firewall. | 7,0% | — |
| CVE-1999-0967 | HIGH 10.0 | microsoft internet_explorer Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol. | 7,0% | — |
| CVE-2026-42980 | HIGH 7.8 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. | 6,9% | — |
| CVE-2003-0503 | HIGH 7.5 | microsoft windows_2000 Buffer overflow in the ShellExecute API function of SHELL32.DLL in Windows 2000 before SP4 may allow attackers to cause a denial of service or execute arbitrary code via a long third argument. | 6,9% | — |
| CVE-2025-21204 | HIGH 7.8 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. | 6,9% | — |
| CVE-1999-0993 | HIGH 7.5 | microsoft exchange_server Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed. | 6,9% | — |
| CVE-2016-0039 | MED 6.1 | microsoft sharepoint_foundation Cross-site scripting (XSS) vulnerability in SharePoint Server in Microsoft SharePoint Foundation 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability." | 6,9% | — |
| CVE-2006-3351 | MED 5.4 | microsoft windows_2003_server Buffer overflow in Windows Explorer (explorer.exe) on Windows XP and 2003 allows user-assisted attackers to cause a denial of service (repeated crash) and possibly execute arbitrary code via a .url file with an InternetShortcut tag containing a long URL and a | 6,9% | — |
| CVE-2006-5884 | HIGH 7.5 | microsoft ie Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Explorer 5.01 through 6 have unknown impact and remote attack vectors, possibly related to (1) Danim.dll and (2) Lmrt.dll, a different set of vulnerabilities than C | 6,9% | — |
| CVE-2018-8595 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Serve | 6,9% | — |
| CVE-2019-1361 | MED 5.5 | microsoft windows_7 An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Information Disclosure Vulnerability'. | 6,9% | — |
| CVE-1999-1055 | HIGH 7.5 | microsoft excel Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability." | 6,9% | — |
| CVE-2024-30034 | MED 5.5 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | 6,9% | — |