56.580 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.463 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2024-20685 | MED 5.9 | microsoft azure_private_5g_core Azure Private 5G Core Denial of Service Vulnerability | 5,5% | — |
| CVE-2020-1042 | CRIT 9.0 | microsoft windows_server_2008 A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is un | 5,5% | — |
| CVE-2019-0920 | MED 4.3 | microsoft internet_explorer A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. | 5,5% | — |
| CVE-2017-0248 | HIGH 7.5 | microsoft .net_framework Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." | 5,5% | — |
| CVE-2018-0839 | MED 4.3 | microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows information disclosure, due to how Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0763. | 5,5% | — |
| CVE-2017-8662 | MED 4.3 | microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to disclose information due to how strings are validated in specific scenarios, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8644 and CVE-2017-8652 | 5,5% | — |
| CVE-2021-26902 | HIGH 7.8 | microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability | 5,5% | — |
| CVE-2018-8530 | MED 4.3 | microsoft edge A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8512. | 5,5% | — |
| CVE-2021-42298 | HIGH 7.8 | microsoft malware_protection_engine Microsoft Defender Remote Code Execution Vulnerability | 5,5% | — |
| CVE-2000-1083 | LOW 2.1 | microsoft data_engine The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacke | 5,5% | — |
| CVE-2017-11791 | LOW 3.1 | microsoft chakracore ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 201 | 5,5% | — |
| CVE-2001-0091 | LOW 2.6 | microsoft internet_explorer The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability. | 5,5% | — |
| CVE-2011-0091 | MED 6.4 | microsoft windows_7 Kerberos in Microsoft Windows Server 2008 R2 and Windows 7 does not prevent a session from changing from strong encryption to DES encryption, which allows man-in-the-middle attackers to spoof network traffic and obtain sensitive information via a DES downgrade | 5,5% | — |
| CVE-2019-11397 | MED 6.5 | microsoft .net_framework GetFile.aspx in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) allows Local File Inclusion via the FileDesc parameter. | 5,5% | — |
| CVE-2020-1322 | MED 6.5 | microsoft 365_apps An information disclosure vulnerability exists when Microsoft Project reads out of bound memory due to an uninitialized variable, aka 'Microsoft Project Information Disclosure Vulnerability'. | 5,5% | — |
| CVE-2023-36435 | HIGH 7.5 | microsoft .net Microsoft QUIC Denial of Service Vulnerability | 5,5% | — |
| CVE-2020-1043 | CRIT 9.0 | microsoft windows_server_2008 A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is un | 5,5% | — |
| CVE-2020-1041 | CRIT 9.0 | microsoft windows_server_2008 A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is un | 5,5% | — |
| CVE-2020-1032 | CRIT 9.0 | microsoft windows_server_2008 A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is un | 5,5% | — |
| CVE-2018-8150 | MED 6.5 | microsoft office A security feature bypass vulnerability exists when the Microsoft Outlook attachment block filter does not properly handle attachments, aka "Microsoft Outlook Security Feature Bypass Vulnerability." This affects Microsoft Office. | 5,5% | — |
| CVE-2022-35751 | HIGH 7.8 | microsoft windows_10_1507 Windows Hyper-V Elevation of Privilege Vulnerability | 5,5% | — |
| CVE-2018-8546 | MED 5.9 | microsoft lync A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Lync, Skype. | 5,5% | — |
| CVE-2020-0813 | HIGH 7.5 | microsoft chakracore An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user’s computer or data.To exploit the vulnerability, an attacker must know | 5,5% | — |
| CVE-2018-8238 | HIGH 7.8 | microsoft lync A security feature bypass vulnerability exists when Skype for Business or Lync do not properly parse UNC path links shared via messages, aka "Skype for Business and Lync Security Feature Bypass Vulnerability." This affects Skype, Microsoft Lync. | 5,5% | — |
| CVE-1999-1233 | HIGH 7.5 | microsoft internet_information_server IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the "Domain Resolution" vulnerability. | 5,5% | — |