56.580 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.463 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-38196 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 5,7% | — |
| CVE-1999-1452 | LOW 2.1 | microsoft windows_nt GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt. | 5,7% | — |
| CVE-2019-0820 | HIGH 7.5 | microsoft .net_core A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981. | 5,7% | — |
| CVE-2018-8126 | HIGH 8.8 | microsoft internet_explorer A security feature bypass vulnerability exists when Internet Explorer fails to validate User Mode Code Integrity (UMCI) policies, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11. | 5,7% | — |
| CVE-2023-33131 | HIGH 8.8 | microsoft office Microsoft Outlook Remote Code Execution Vulnerability | 5,7% | — |
| CVE-2019-0906 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 5,7% | — |
| CVE-2014-0296 | MED 5.1 | microsoft windows_7 The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly encrypt sessions, which makes it easier for man-in-the-middle attackers to obtain sensitive information b | 5,7% | — |
| CVE-2017-8651 | HIGH 7.5 | microsoft internet_explorer Internet Explorer in Microsoft Windows Server 2008 SP2 and Windows Server 2012 allows an attacker to execute arbitrary code in the context of the current user due to Internet Explorer improperly accessing objects in memory, aka "Internet Explorer Memory Corrup | 5,7% | — |
| CVE-2021-40480 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 5,7% | — |
| CVE-2001-0332 | MED 5.0 | microsoft internet_explorer Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain usin | 5,7% | — |
| CVE-2017-8549 | HIGH 7.5 | microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system when Microsoft Edge improperly handles objects in memory, aka "Scripting Engine Memory C | 5,7% | — |
| CVE-2017-0185 | MED 5.8 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a gu | 5,7% | — |
| CVE-1999-0519 | HIGH 7.5 | microsoft outlook A NETBIOS/SMB share password is the default, null, or missing. | 5,7% | — |
| CVE-2017-8648 | MED 4.3 | microsoft windows_10 Microsoft Edge in Microsoft Windows Version 1703 allows an attacker to obtain information to further compromise the user's system, due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE | 5,7% | — |
| CVE-2017-8597 | MED 4.3 | microsoft windows_10 Microsoft Edge in Microsoft Windows 10 Version 1703 allows an attacker to obtain information to further compromise the user's system, due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This | 5,7% | — |
| CVE-2018-0998 | MED 4.3 | microsoft edge An information disclosure vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-0892. | 5,7% | — |
| CVE-2020-1408 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'. | 5,7% | — |
| CVE-2017-17688 | MED 5.9 | apple mail The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection | 5,7% | — |
| CVE-2016-0042 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted applicat | 5,7% | — |
| CVE-2001-0246 | MED 5.0 | microsoft internet_explorer Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka | 5,6% | — |
| CVE-2001-0047 | HIGH 7.5 | microsoft windows_nt The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities. | 5,6% | — |
| CVE-2017-11856 | HIGH 7.5 | microsoft internet_explorer Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain t | 5,6% | — |
| CVE-2019-1466 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1465, CVE-2019-1467. | 5,6% | — |
| CVE-2019-1465 | MED 6.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1466, CVE-2019-1467. | 5,6% | — |
| CVE-2000-1104 | HIGH 7.5 | microsoft internet_information_server Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the | 5,6% | — |