Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2018-8421EPSS 26%
A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulne…
.net Framework
Patch available
CRITICAL 9.8
CVE-2018-8273EPSS 29%
A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL S…
Sql Server
Patch available
CRITICAL 9.8
CVE-2018-8302EPSS 23%
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Micros…
Exchange Server
Patch available
CRITICAL 9.8
CVE-2018-8319EPSS 6%
A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, aka "MSR J…
Research Javascript Cryptography Library
Patch available
CRITICAL 9.8
CVE-2018-8327EPSS 21%
A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." Thi…
Powershell
1.7.0+
CRITICAL 9.8
CVE-2018-12571EPSS 27%
uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries fo…
Forefront Unified Access Gateway
No fix yet
CRITICAL 9.8
CVE-2018-8154EPSS 22%
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Micros…
Exchange Server
Patch available
CRITICAL 9.8
CVE-2017-11899EPSS 5%
Device Guard in Windows 10 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerabi…
Windows 10
Patch available
CRITICAL 9.8
CVE-2017-11767EPSS 9%
ChakraCore allows an attacker to gain the same user rights as the current user, due to the way that the ChakraCore scripting engine handles objects i…
Chakracore
Mitigation only
CRITICAL 9.8
CVE-2017-11771EPSS 55%
The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, …
Windows 10
Patch available
CRITICAL 9.8
CVE-2017-8686EPSS 25%
The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DH…
Windows Server 2012
Patch available
CRITICAL 9.8
CVE-2017-8658EPSS 19%
A remote code execution vulnerability exists in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Eng…
Chakracore
after 1.7.0
CRITICAL 9.8
CVE-2017-0028EPSS 17%
A remote code execution vulnerability exists when Microsoft scripting engine improperly accesses objects in memory. The vulnerability could corrupt m…
Edge
Patch available
CRITICAL 9.8
CVE-2017-8589EPSS 24%
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,…
Windows 10
Patch available
CRITICAL 9.8
CVE-2017-8543 KEVEPSS 65%
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, W…
Windows 10 1507
Patch available
CRITICAL 9.8
CVE-2017-0223EPSS 13%
A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka "Scri…
Edge
Patch available
CRITICAL 9.8
CVE-2017-0252EPSS 12%
A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka "Scri…
Edge
Patch available
CRITICAL 9.8
CVE-2017-7269 KEVEPSS 100%
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 200…
Internet Information Services
Patch available
CRITICAL 9.8
CVE-2017-6517EPSS 42%
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted sy…
Skype
No fix yet
CRITICAL 9.0
CVE-2017-0021
Hyper-V in Microsoft Windows 10 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary…
Windows 10
Patch available
CRITICAL 9.6
CVE-2016-7277EPSS 18%
Microsoft Office 2016 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka …
Office
Mitigation only
CRITICAL 9.8
CVE-2016-7182EPSS 26%
The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R…
Live Meeting
Mitigation only
CRITICAL 9.1
CVE-2016-3312EPSS 8%
ActiveSyncProvider in Microsoft Windows 10 Gold and 1511 allows attackers to discover credentials by leveraging failure of Universal Outlook to obtai…
Windows 10
Mitigation only
CRITICAL 9.8
CVE-2016-3236EPSS 75%
The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window…
Windows 10
Mitigation only
CRITICAL 9.3
CVE-2016-0088EPSS 8%
Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbitrary code on the host OS via …
Windows 10
Mitigation only
CRITICAL 9.8
CVE-2016-0132EPSS 20%
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified elements of XML document…
.net Framework
Mitigation only
CRITICAL 9.6
CVE-2016-0003EPSS 34%
Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka "Microsoft Edge Memory Corruption Vulnerability."
Edge
Mitigation only
CRITICAL 9.8
CVE-2015-1635 KEVEPSS 100%
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers …
Windows 7
Patch available
CRITICAL 9.8
CVE-2014-1776 KEVEPSS 88%
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of servi…
Internet Explorer
Patch available
CRITICAL 9.8
CVE-2012-1891EPSS 29%
Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote att…
Data Access Components
Mitigation only