Vulnerability index

Browse CVEs

3,025 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2018-8343 An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buff… Windows 10 Mitigation only Fix from $1,9502018-08-15 HIGH 7.5 CVE-2018-8345EPSS 14% A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote… Windows 10 Mitigation only Fix from $1,9502018-08-15 HIGH 7.0 CVE-2018-8339 An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an ins… Windows 10 Mitigation only Fix from $1,9502018-08-15 HIGH 8.8 CVE-2018-8311EPSS 17% A remote code execution vulnerability exists when Skype for Business and Microsoft Lync clients fail to properly sanitize specially crafted content, … Lync Mitigation only Fix from $1,9502018-07-11 HIGH 7.8 CVE-2018-8282 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka "Win32k… Windows 10 Mitigation only Fix from $1,9502018-07-11 MEDIUM 6.5 CVE-2018-8305EPSS 8% An information disclosure vulnerability exists in Windows Mail Client when a message is opened, aka "Windows Mail Client Information Disclosure Vulne… Windows Calendar Mitigation only Fix from $1,6002018-07-11 HIGH 8.8 CVE-2018-8260EPSS 15% A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".NET Framework Remot… .net Framework Mitigation only Fix from $1,9502018-07-11 CRITICAL 9.8 CVE-2018-12571EPSS 30% uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries fo… Forefront Unified Access Gateway No fix yet Fix from $2,3002018-07-05 HIGH 7.8 CVE-2018-0592EPSS 5% Untrusted search path vulnerability in Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. Onedrive Mitigation only Fix from $1,9502018-06-26 HIGH 7.8 CVE-2018-0593EPSS 5% Untrusted search path vulnerability in the installer of Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL in an unspeci… Onedrive Mitigation only Fix from $1,9502018-06-26 HIGH 7.8 CVE-2018-0594EPSS 5% Untrusted search path vulnerability in Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. Skype Mitigation only Fix from $1,9502018-06-26 HIGH 7.8 CVE-2018-0595EPSS 5% Untrusted search path vulnerability in the installer of Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecif… Skype Mitigation only Fix from $1,9502018-06-26 HIGH 7.8 CVE-2018-0596EPSS 5% Untrusted search path vulnerability in the installer of Visual Studio Community allows an attacker to gain privileges via a Trojan horse DLL in an un… Visual Studio Community Mitigation only Fix from $1,9502018-06-26 HIGH 7.8 CVE-2018-0597EPSS 5% Untrusted search path vulnerability in the installer of Visual Studio Code allows an attacker to gain privileges via a Trojan horse DLL in an unspeci… Visual Studio Code Mitigation only Fix from $1,9502018-06-26 HIGH 7.8 CVE-2018-0598EPSS 9% Untrusted search path vulnerability in Self-extracting archive files created by IExpress bundled with Microsoft Windows allows an attacker to gain pr… Windows Mitigation only Fix from $1,9502018-06-26 HIGH 8.1 CVE-2018-8225EPSS 24% A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Wind… Windows 10 Mitigation only Fix from $1,9502018-06-14 HIGH 7.0 CVE-2018-1036 An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Wind… Windows 10 Mitigation only Fix from $1,9502018-06-14 HIGH 7.0 CVE-2018-8169 An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library driver improperly handles objects in memory, aka … Windows 10 Mitigation only Fix from $1,9502018-06-14 MEDIUM 5.5 CVE-2018-8205 A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Service Vulnerability." This affec… Windows 10 Mitigation only Fix from $1,6002018-06-14 MEDIUM 5.3 CVE-2018-1040EPSS 7% A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs hashing, aka "Windows Code Integrity Module Denia… Windows 10 Mitigation only Fix from $1,6002018-06-14 HIGH 7.0 CVE-2018-8124 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation… Windows 10 Mitigation only Fix from $1,9502018-05-09 HIGH 7.0 CVE-2018-7249 An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped i… Windows 7 No fix yet Fix from $1,9502018-02-26 MEDIUM 5.5 CVE-2018-7250 An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped i… Windows 7 Mitigation only Fix from $1,6002018-02-26 HIGH 7.5 CVE-2018-0858EPSS 15% ChakraCore allows remote code execution, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruptio… Chakracore Mitigation only Fix from $1,9502018-02-15 HIGH 7.5 CVE-2018-0859EPSS 18% Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how … Chakracore No fix yet Fix from $1,9502018-02-15 HIGH 7.5 CVE-2018-0834EPSS 55% Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how … Chakracore No fix yet Fix from $1,9502018-02-15 HIGH 7.5 CVE-2018-0818 Microsoft ChakraCore allows an attacker to bypass Control Flow Guard (CFG) in conjunction with another vulnerability to run arbitrary code on a targe… Chakracore Mitigation only Fix from $1,9502018-01-10 HIGH 7.1 CVE-2018-0751 The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Win… Windows 10 No fix yet Fix from $1,9502018-01-04 HIGH 7.0 CVE-2018-0744EPSS 15% The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows… Windows 10 No fix yet Fix from $1,9502018-01-04 MEDIUM 5.9 CVE-2018-0753EPSS 9% Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 … Windows 10 Mitigation only Fix from $1,6002018-01-04