58.507 CVE seguite
796 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
Vulnerabilità Microsoft
16.469 CVE
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordina dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2005-1983 | HIGH 10.0 | microsoft windows_2000 Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as e | 93,0% | — |
| CVE-2023-35628 | HIGH 8.1 | microsoft windows_10_1507 Windows MSHTML Platform Remote Code Execution Vulnerability | 92,8% | — |
| CVE-2022-21907 | CRIT 9.8 | microsoft windows_10 HTTP Protocol Stack Remote Code Execution Vulnerability | 92,8% | — |
| CVE-2023-28302 | HIGH 7.5 | microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 92,6% | — |
| CVE-2023-21758 | HIGH 7.5 | microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | 92,5% | — |
| CVE-2009-3103 | HIGH 10.0 | microsoft windows_server_2008 Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) v | 92,3% | — |
| CVE-2017-0004 | HIGH 7.5 | microsoft windows_7 The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to cause a denial of service (reboot) via a crafted authentication request, aka "Local Security | 91,4% | — |
| CVE-2022-26809 | CRIT 9.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 91,0% | — |
| CVE-2009-3023 | HIGH 9.0 | microsoft internet_information_server Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS F | 90,9% | — |
| CVE-2001-0333 | HIGH 7.5 | microsoft internet_information_server Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice. | 90,8% | — |
| CVE-2000-0402 | LOW 2.1 | microsoft sql_server The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability. | 90,6% | — |
| CVE-2006-2372 | HIGH 10.0 | microsoft dhcp_client_service Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response. | 90,2% | — |
| CVE-2020-17132 | CRIT 9.1 | microsoft exchange_server Microsoft Exchange Remote Code Execution Vulnerability | 89,9% | — |
| CVE-2023-21547 | HIGH 7.5 | microsoft windows_10_1607 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | 89,3% | — |
| CVE-2006-0026 | MED 6.5 | microsoft internet_information_server Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP). | 89,3% | — |
| CVE-2023-21769 | HIGH 7.5 | microsoft windows_10_1607 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | 88,7% | — |
| CVE-2022-30216 | HIGH 8.8 | microsoft windows_10 Windows Server Service Tampering Vulnerability | 88,6% | — |
| CVE-2003-0718 | MED 5.0 | microsoft internet_information_server The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a l | 87,9% | — |
| CVE-2000-1209 | HIGH 10.0 | compaq insight_manager The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight | 87,3% | — |
| CVE-2000-0778 | MED 5.0 | microsoft internet_information_services IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability. | 87,3% | — |
| CVE-2008-5416 | HIGH 9.0 | microsoft sql_server Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop Engine (MSDE 2000) SP4; SQL Server 2005 SP2 and 9.00.1399.06; SQL Server 2000 Desktop Engine (WMSDE) on Windows Server 2003 SP1 and SP2; and | 87,0% | — |
| CVE-2005-4360 | HIGH 7.8 | microsoft internet_information_services The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to ".dll" followed by arguments such as "~0" through "~9", which causes ntdll.dll to prod | 86,7% | — |
| CVE-2010-0483 | HIGH 7.6 | microsoft windows_2000 vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC sha | 86,6% | — |
| CVE-2023-36035 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 86,6% | — |
| CVE-2012-0152 | MED 4.3 | microsoft windows_7 The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka "Terminal Server Denial of Service | 86,3% | — |