imPC@ndo IT

Microsoft vulnerabilities

15.371 CVE

CVE-2021-34484
Exploited High 7.8

Windows User Profile Service Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · and 12 more
0.22EPSS
CVE-2025-30397
Exploited High 7.5

Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.21EPSS
CVE-2012-1854
Exploited High 7.8

Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basic for Applications (VBA); and Summit Microsoft Visual Basic for Applications SDK allows local users to gain privileges v…

microsoft office · microsoft visual_basic_for_applications · microsoft visual_basic_for_applications_sdk
0.21EPSS
CVE-2023-36563
Exploited Medium 6.5

Microsoft WordPad Information Disclosure Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 8 more
0.21EPSS
CVE-2016-3309
Ransomware High 7.8

The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted appl…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_7 · and 5 more
0.21EPSS
CVE-2024-7971
Exploited Critical 9.6

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

google chrome · microsoft edge
0.21EPSS
CVE-2021-31956
Exploited High 7.8

Windows NTFS Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · and 12 more
0.20EPSS
CVE-2021-41379
Ransomware Medium 5.5

Windows Installer Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · and 14 more
0.20EPSS
CVE-2017-0210
Exploited High 8.8

An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Pr…

microsoft internet_explorer
0.20EPSS
CVE-2023-6345
Exploited Critical 9.6

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

debian debian_linux · fedoraproject fedora · google chrome · microsoft edge_chromium
0.19EPSS
CVE-2019-1215
Ransomware High 7.8

An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1253, CVE-2019-1278, CVE-2019-1303.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · and 12 more
0.19EPSS
CVE-2019-1322
Ransomware High 7.8

An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1320, CVE-2019-1340.

microsoft windows_10_1803 · microsoft windows_10_1809 · microsoft windows_10_1903 · microsoft windows_server_1803 · and 2 more
0.19EPSS
CVE-2023-36761
Exploited Medium 6.5

Microsoft Word Information Disclosure Vulnerability

microsoft 365_apps · microsoft office · microsoft office_long_term_servicing_channel · microsoft word
0.19EPSS
CVE-2022-22718
Exploited High 7.8

Windows Print Spooler Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · and 13 more
0.18EPSS
CVE-2018-8440
Ransomware High 7.8

An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Serve…

microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · microsoft windows_10_1803 · and 6 more
0.18EPSS
CVE-2024-7965
Exploited High 8.8

Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

google chrome · microsoft edge_chromium
0.18EPSS
CVE-2017-0022
Exploited Medium 6.5

Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in me…

microsoft windows_8.1 · microsoft windows_server_2008 · microsoft windows_server_2012 · microsoft xml_core_services
0.18EPSS
CVE-2022-22047
Exploited High 7.8

Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 12 more
0.17EPSS
CVE-2023-36036
Exploited High 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 9 more
0.17EPSS
CVE-2020-0986
Exploited High 7.8

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264,…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · and 13 more
0.16EPSS
CVE-2023-35311
Exploited High 8.8

Microsoft Outlook Security Feature Bypass Vulnerability

microsoft 365_apps · microsoft office · microsoft office_long_term_servicing_channel · microsoft outlook
0.16EPSS
CVE-2026-21513
Exploited High 8.8

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · and 9 more
0.15EPSS
CVE-2015-2360
Exploited High 8.8

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · and 5 more
0.15EPSS
CVE-2022-38028
Exploited High 7.8

Windows Print Spooler Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 9 more
0.15EPSS
CVE-2023-38180
Exploited High 7.5

.NET and Visual Studio Denial of Service Vulnerability

fedoraproject fedora · microsoft .net · microsoft asp.net_core · microsoft visual_studio_2022
0.15EPSS