56.596 CVE seguite
773 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
15.471 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2021-30614 | HIGH 8.8 | fedoraproject fedora Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip | 4,5% | — |
| CVE-2020-16911 | HIGH 8.8 | microsoft windows_10 <p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could th | 4,5% | — |
| CVE-2020-1432 | MED 4.3 | microsoft internet_explorer An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explorer Information Disclosure Vulnerability'. | 4,5% | — |
| CVE-2022-26927 | HIGH 8.8 | microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability | 4,4% | — |
| CVE-2016-0152 | HIGH 7.8 | microsoft windows_server_2008 Internet Information Services (IIS) in Microsoft Windows Vista SP2 and Server 2008 SP2 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Windows DLL Loading Remote Code Execution Vulnerability." | 4,4% | — |
| CVE-2005-0047 | HIGH 7.2 | microsoft windows_2000 Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability." | 4,4% | — |
| CVE-2020-0875 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system (low-integrity to medium-integrity).</p> <p> | 4,4% | — |
| CVE-2017-0182 | MED 5.8 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a | 4,4% | — |
| CVE-2020-16855 | MED 5.5 | microsoft office <p>An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory. An attacker who successfully exploited the vulnerability could view out of | 4,4% | — |
| CVE-2018-8580 | MED 4.3 | microsoft sharepoint_server An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosu | 4,4% | — |
| CVE-2019-1204 | MED 4.3 | microsoft office An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Out | 4,4% | — |
| CVE-2026-40364 | HIGH 8.4 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 4,4% | — |
| CVE-2019-0716 | MED 5.8 | microsoft windows_10 A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on | 4,4% | — |
| CVE-2017-0183 | MED 5.8 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a | 4,4% | — |
| CVE-2000-0737 | MED 4.6 | microsoft windows_2000 The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability. | 4,4% | — |
| CVE-2016-0095 | HIGH 7.8 | microsoft windows_10 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application | 4,4% | — |
| CVE-2022-21883 | HIGH 7.5 | microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | 4,4% | — |
| CVE-2021-34520 | HIGH 8.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 4,4% | — |
| CVE-2020-0665 | HIGH 8.1 | microsoft windows_10 An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privi | 4,4% | — |
| CVE-2021-34470 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 4,4% | — |
| CVE-2023-38143 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 4,4% | — |
| CVE-2020-16856 | HIGH 7.8 | microsoft visual_studio <p>A remote code execution vulnerability exists in Visual Studio when it improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged o | 4,4% | — |
| CVE-2000-0767 | LOW 2.6 | microsoft internet_explorer The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the "Scriptlet Rendering" vulnerability. | 4,4% | — |
| CVE-2020-1217 | HIGH 7.8 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Information Disclosure Vulnerability'. | 4,4% | — |
| CVE-2019-0649 | HIGH 8.1 | microsoft chakracore A vulnerability exists in Microsoft Chakra JIT server, aka 'Scripting Engine Elevation of Privileged Vulnerability'. | 4,4% | — |