Vulnerability index

Browse CVEs

458 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2018-8421EPSS 26% A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulne… .net Framework Patch available Fix from $2,3002018-09-13 CRITICAL 9.8 CVE-2018-8273EPSS 29% A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL S… Sql Server Patch available Fix from $2,3002018-08-15 CRITICAL 9.8 CVE-2018-8302EPSS 23% A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Micros… Exchange Server Patch available Fix from $2,3002018-08-15 CRITICAL 9.8 CVE-2018-8319EPSS 6% A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, aka "MSR J… Research Javascript Cryptography Library Patch available Fix from $2,3002018-07-11 CRITICAL 9.8 CVE-2018-8327EPSS 21% A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." Thi… Powershell 1.7.0+ Fix from $2,3002018-07-11 CRITICAL 9.8 CVE-2018-12571EPSS 27% uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries fo… Forefront Unified Access Gateway No fix yet Fix from $2,3002018-07-05 CRITICAL 9.8 CVE-2018-8154EPSS 22% A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Micros… Exchange Server Patch available Fix from $2,3002018-05-09 CRITICAL 9.8 CVE-2017-11899EPSS 5% Device Guard in Windows 10 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerabi… Windows 10 Patch available Fix from $2,3002017-12-12 CRITICAL 9.8 CVE-2017-11767EPSS 9% ChakraCore allows an attacker to gain the same user rights as the current user, due to the way that the ChakraCore scripting engine handles objects i… Chakracore Mitigation only Fix from $2,3002017-11-02 CRITICAL 9.8 CVE-2017-11771EPSS 55% The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, … Windows 10 Patch available Fix from $2,3002017-10-13 CRITICAL 9.8 CVE-2017-8686EPSS 25% The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DH… Windows Server 2012 Patch available Fix from $2,3002017-09-13 CRITICAL 9.8 CVE-2017-8658EPSS 19% A remote code execution vulnerability exists in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Eng… Chakracore after 1.7.0 Fix from $2,3002017-08-11 CRITICAL 9.8 CVE-2017-0028EPSS 17% A remote code execution vulnerability exists when Microsoft scripting engine improperly accesses objects in memory. The vulnerability could corrupt m… Edge Patch available Fix from $2,3002017-07-17 CRITICAL 9.8 CVE-2017-8589EPSS 24% Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,… Windows 10 Patch available Fix from $2,3002017-07-11 CRITICAL 9.8 CVE-2017-8543 KEVEPSS 65% Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, W… Windows 10 1507 Patch available Fix from $2,3002017-06-15 CRITICAL 9.8 CVE-2017-0223EPSS 13% A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka "Scri… Edge Patch available Fix from $2,3002017-05-15 CRITICAL 9.8 CVE-2017-0252EPSS 12% A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka "Scri… Edge Patch available Fix from $2,3002017-05-15 CRITICAL 9.8 CVE-2017-7269 KEVEPSS 100% Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 200… Internet Information Services Patch available Fix from $2,3002017-03-27 CRITICAL 9.8 CVE-2017-6517EPSS 42% Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted sy… Skype No fix yet Fix from $2,3002017-03-23 CRITICAL 9.0 CVE-2017-0021 Hyper-V in Microsoft Windows 10 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary… Windows 10 Patch available Fix from $2,3002017-03-17 CRITICAL 9.6 CVE-2016-7277EPSS 18% Microsoft Office 2016 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka … Office Mitigation only Fix from $2,3002016-12-20 CRITICAL 9.8 CVE-2016-7182EPSS 26% The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R… Live Meeting Mitigation only Fix from $2,3002016-10-14 CRITICAL 9.1 CVE-2016-3312EPSS 8% ActiveSyncProvider in Microsoft Windows 10 Gold and 1511 allows attackers to discover credentials by leveraging failure of Universal Outlook to obtai… Windows 10 Mitigation only Fix from $2,3002016-08-09 CRITICAL 9.8 CVE-2016-3236EPSS 75% The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window… Windows 10 Mitigation only Fix from $2,3002016-06-16 CRITICAL 9.3 CVE-2016-0088EPSS 8% Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbitrary code on the host OS via … Windows 10 Mitigation only Fix from $2,3002016-04-12 CRITICAL 9.8 CVE-2016-0132EPSS 20% Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified elements of XML document… .net Framework Mitigation only Fix from $2,3002016-03-09 CRITICAL 9.6 CVE-2016-0003EPSS 34% Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka "Microsoft Edge Memory Corruption Vulnerability." Edge Mitigation only Fix from $2,3002016-01-13 CRITICAL 9.8 CVE-2015-1635 KEVEPSS 100% HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers … Windows 7 Patch available Fix from $2,3002015-04-14 CRITICAL 9.8 CVE-2014-1776 KEVEPSS 88% Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of servi… Internet Explorer Patch available Fix from $2,3002014-04-27 CRITICAL 9.8 CVE-2012-1891EPSS 29% Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote att… Data Access Components Mitigation only Fix from $2,3002012-07-10