imPC@ndo IT

Microsoft vulnerabilities

15.313 CVE

CVE-2023-44487
Exploited High 7.5

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

akka http_server · amazon opensearch_data_prepper · apache apisix · apache solr · and 161 more
1.00EPSS
CVE-2015-1635
Exploited Critical 9.8

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_server_2008 · and 1 more
1.00EPSS
CVE-2021-34473
Ransomware Critical 9.1

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2021-26855
Ransomware Critical 9.1

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2019-0708
Ransomware Critical 9.8

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code …

huawei agile_controller-campus_firmware · huawei bh620_v2_firmware · huawei bh621_v2_firmware · huawei bh622_v2_firmware · and 63 more
1.00EPSS
CVE-2021-34523
Ransomware Critical 9.0

Microsoft Exchange Server Elevation of Privilege Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2025-53770
Ransomware Critical 9.8

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a co…

microsoft sharepoint_server
1.00EPSS
CVE-2022-41082
Ransomware High 8.0

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2012-0158
Exploited High 8.8

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2…

microsoft biztalk_server · microsoft commerce_server · microsoft commerce_server_2009 · microsoft office · and 6 more
1.00EPSS
CVE-2020-0688
Ransomware High 8.8

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.

microsoft exchange_server
1.00EPSS
CVE-2022-41040
Ransomware High 8.8

Microsoft Exchange Server Elevation of Privilege Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2021-27065
Ransomware High 7.8

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2017-11882
Ransomware High 7.8

Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memo…

microsoft office
1.00EPSS
CVE-2025-59287
Exploited Critical 9.8

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019 · microsoft windows_server_2022 · and 2 more
1.00EPSS
CVE-2021-38647
Ransomware Critical 9.8

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

microsoft azure_automation_state_configuration · microsoft azure_automation_update_management · microsoft azure_diagnostics_\(lad\) · microsoft azure_security_center · and 6 more
1.00EPSS
CVE-2017-0199
Ransomware High 7.8

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, ak…

microsoft office · microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_server_2012 · and 2 more
1.00EPSS
CVE-2025-49704
Ransomware High 8.8

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

microsoft sharepoint_server
1.00EPSS
CVE-2025-49706
Ransomware Medium 6.5

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

microsoft sharepoint_enterprise_server · microsoft sharepoint_server
1.00EPSS
CVE-2019-0604
Ransomware Critical 9.8

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.

microsoft sharepoint_enterprise_server · microsoft sharepoint_foundation · microsoft sharepoint_server
1.00EPSS
CVE-2017-7269
Exploited Critical 9.8

Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PRO…

microsoft internet_information_services
1.00EPSS
CVE-2020-0796
Ransomware Critical 10.0

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

microsoft windows_10_1903 · microsoft windows_10_1909 · microsoft windows_server_1903 · microsoft windows_server_1909
1.00EPSS
CVE-2021-34527
Ransomware High 8.8

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could the…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 11 more
1.00EPSS
CVE-2021-31207
Ransomware Medium 6.6

Microsoft Exchange Server Security Feature Bypass Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2023-4863
Exploited High 8.8

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

bandisoft honeyview · bentley seequent_leapfrog · debian debian_linux · fedoraproject fedora · and 8 more
1.00EPSS
CVE-2017-0147
Ransomware High 7.5

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sen…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_7 · and 14 more
1.00EPSS