EN
58.476 CVE seguite
793 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia

Vulnerabilità Microsoft

16.464 CVE

Vulnerabilità Microsoft
Identificativo Gravità, ordina dal più alto Prodotto e difetto EPSS, ordina dal più alto In KEV dal, ordina dal più alto
CVE-2017-0199 HIGH 7.8 ransomware microsoft office Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, ak 99,5%
CVE-2024-21412 HIGH 8.1 ransomware microsoft windows_10_1809 Internet Shortcut Files Security Feature Bypass Vulnerability 99,4%
CVE-2020-1472 MED 5.5 ransomware canonical ubuntu_linux An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run 99,4%
CVE-2017-0148 HIGH 8.1 ransomware microsoft server_message_block The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute ar 99,4%
CVE-2022-30190 HIGH 7.8 ransomware microsoft windows_10_1507 A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The 99,2%
CVE-2017-0144 HIGH 8.8 ransomware microsoft server_message_block The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute ar 99,2%
CVE-2020-0646 CRIT 9.8 microsoft .net_framework A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'. 99,2%
CVE-2025-49706 MED 6.5 ransomware microsoft sharepoint_enterprise_server Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 99,1%
CVE-2020-0618 HIGH 8.8 ransomware microsoft sql_server A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'. 99,0%
CVE-2023-36884 HIGH 7.5 ransomware microsoft windows_10_1507 Windows Search Remote Code Execution Vulnerability 98,9%
CVE-2008-4250 CRIT 9.8 microsoft windows_2000 The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canoni 98,8%
CVE-2024-29059 HIGH 7.5 microsoft .net_framework .NET Framework Information Disclosure Vulnerability 98,6%
CVE-2021-33766 HIGH 7.3 microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability 98,1%
CVE-2021-40444 HIGH 8.8 ransomware microsoft windows_10_1507 Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An at 97,5%
CVE-2023-23397 CRIT 9.8 microsoft 365_apps Microsoft Outlook Elevation of Privilege Vulnerability 97,2%
CVE-2010-3962 HIGH 8.1 microsoft internet_explorer Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Unin 96,8%
CVE-2020-1350 CRIT 10.0 microsoft windows_server_2008 A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'. 96,7%
CVE-2015-1641 HIGH 7.8 microsoft office Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 al 96,7%
CVE-2021-26857 HIGH 7.8 ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 95,8%
CVE-2015-0313 CRIT 9.8 adobe flash_player Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil 95,3%
CVE-2018-0798 HIGH 8.8 microsoft office Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". 95,1%
CVE-2014-6332 HIGH 8.8 microsoft windows_7 OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary co 95,0%
CVE-2024-21413 CRIT 9.8 microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability 94,7%
CVE-2016-0189 HIGH 7.5 ransomware microsoft internet_explorer The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scr 94,1%
CVE-2020-1147 HIGH 7.8 microsoft .net_core A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulner 94,0%