Vulnerability index

Browse CVEs

3,025 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Chakracore CRITICAL 9.8
CVE-2017-11767EPSS 10%

ChakraCore allows an attacker to gain the same user rights as the current user, due to the way that the ChakraCore scripting engine handles objects i…

Mitigation only
Fix from $2,300 2017-11-02
Windows Defender HIGH 7.8
CVE-2017-8558EPSS 44%

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2…

No fix yet
Fix from $1,950 2017-06-29
Skype HIGH 8.8
CVE-2017-9948EPSS 6%

A stack buffer overflow vulnerability has been discovered in Microsoft Skype 7.2, 7.35, and 7.36 before 7.37, involving MSFTEDIT.DLL mishandling of r…

Mitigation only
Fix from $1,950 2017-06-26
Asp.net Model View Controller HIGH 7.3
CVE-2017-0249

An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.

No fix yet
Fix from $1,950 2017-05-12
Asp.net Model View Controller MEDIUM 5.3
CVE-2017-0256

A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.

Mitigation only
Fix from $1,600 2017-05-12
Skype CRITICAL 9.8
CVE-2017-6517EPSS 46%

Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted sy…

No fix yet
Fix from $2,300 2017-03-23
Windows 10 HIGH 7.8
CVE-2017-0102

Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 …

Mitigation only
Fix from $1,950 2017-03-17
Skype HIGH 7.8
CVE-2016-5720

Multiple untrusted search path vulnerabilities in Microsoft Skype allow local users to execute arbitrary code and conduct DLL hijacking attacks via a…

Mitigation only
Fix from $1,950 2017-01-23
Edge HIGH 8.8
CVE-2017-0002EPSS 15%

Microsoft Edge allows remote attackers to bypass the Same Origin Policy via vectors involving the about:blank URL and data: URLs, aka "Microsoft Edge…

Mitigation only
Fix from $1,950 2017-01-10
Sharepoint Enterprise Server HIGH 7.8
CVE-2017-0003EPSS 25%

Microsoft Word 2016 and SharePoint Enterprise Server 2016 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Off…

Mitigation only
Fix from $1,950 2017-01-10
Publisher HIGH 7.8
CVE-2016-7289EPSS 25%

Microsoft Publisher 2010 SP2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted documen…

Mitigation only
Fix from $1,950 2016-12-20
Windows 10 HIGH 7.8
CVE-2016-7292

The Installer in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window…

Mitigation only
Fix from $1,950 2016-12-20
Office HIGH 7.8
CVE-2016-7298EPSS 23%

Microsoft Office 2007 SP3, Office 2010 SP2, Word Viewer, Office for Mac 2011, and Office 2016 for Mac allow remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2016-12-20
Auto Updater For Mac HIGH 7.8
CVE-2016-7300

Untrusted search path vulnerability in Microsoft Auto Updater for Mac allows local users to gain privileges via a Trojan horse executable file, aka "…

Mitigation only
Fix from $1,950 2016-12-20
Edge HIGH 7.5
CVE-2016-7286EPSS 69%

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft…

No fix yet
Fix from $1,950 2016-12-20
Edge HIGH 7.5
CVE-2016-7287EPSS 69%

The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of serv…

No fix yet
Fix from $1,950 2016-12-20
Edge HIGH 7.5
CVE-2016-7288EPSS 70%

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft…

No fix yet
Fix from $1,950 2016-12-20
Edge HIGH 7.5
CVE-2016-7296EPSS 17%

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft…

Mitigation only
Fix from $1,950 2016-12-20
Edge HIGH 7.5
CVE-2016-7297EPSS 27%

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft…

Mitigation only
Fix from $1,950 2016-12-20
Office HIGH 7.1
CVE-2016-7290EPSS 23%

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Ser…

Mitigation only
Fix from $1,950 2016-12-20
Office HIGH 7.1
CVE-2016-7291EPSS 23%

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Ser…

Mitigation only
Fix from $1,950 2016-12-20
Edge MEDIUM 6.1
CVE-2016-7280EPSS 9%

Cross-site scripting (XSS) vulnerability in Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, ak…

Mitigation only
Fix from $1,600 2016-12-20
Edge MEDIUM 6.1
CVE-2016-7282EPSS 10%

Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to inject arbitrary w…

Mitigation only
Fix from $1,600 2016-12-20
Windows 10 MEDIUM 5.5
CVE-2016-7295

The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv…

Mitigation only
Fix from $1,600 2016-12-20
Edge MEDIUM 5.3
CVE-2016-7281EPSS 14%

The Web Workers implementation in Microsoft Internet Explorer 10 and 11 and Microsoft Edge allows remote attackers to bypass the Same Origin Policy v…

Mitigation only
Fix from $1,600 2016-12-20
Office CRITICAL 9.6
CVE-2016-7277EPSS 18%

Microsoft Office 2016 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka …

Mitigation only
Fix from $2,300 2016-12-20
Windows 10 HIGH 8.8
CVE-2016-7272EPSS 39%

The Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R…

Mitigation only
Fix from $1,950 2016-12-20
Windows 10 HIGH 8.8
CVE-2016-7273EPSS 19%

The Graphics component in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows remote attackers to execute arbitrary code via a c…

Mitigation only
Fix from $1,950 2016-12-20
Windows 10 HIGH 8.8
CVE-2016-7274EPSS 42%

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT…

No fix yet
Fix from $1,950 2016-12-20
Windows 10 HIGH 7.8
CVE-2016-7259

The Graphics Component in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Win…

No fix yet
Fix from $1,950 2016-12-20