Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Office MEDIUM 5.5
CVE-2017-11934EPSS 6%

Microsoft Office 2013 RT SP1, Microsoft Office 2013 SP1, and Microsoft Office 2016 allow an information disclosure vulnerability due to the way certa…

Patch available
Fix from $1,600 2017-12-12
Chakracore MEDIUM 5.3
CVE-2017-11919EPSS 6%

ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and…

Fix: 1.7.5+
Fix from $1,600 2017-12-12
Windows 10 MEDIUM 6.6
CVE-2017-11885EPSS 39%

Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wi…

Patch available
Fix from $1,600 2017-12-12
Malware Protection Engine HIGH 7.8
CVE-2017-11940EPSS 17%

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows …

Fix: after 1.1.14306.0
Fix from $1,950 2017-12-08
Malware Protection Engine HIGH 7.8
CVE-2017-11937EPSS 24%

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows …

Fix: after 1.1.14306.0
Fix from $1,950 2017-12-07
Asp.net Core HIGH 7.5
CVE-2017-8700EPSS 9%

ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted conte…

Patch available
Fix from $1,950 2017-11-15
Office HIGH 8.8
CVE-2017-11854EPSS 8%

Microsoft Word 2007 Service Pack 3, Microsoft Word 2010 Service Pack 2, Microsoft Office 2010 Service Pack 2, and Microsoft Office Compatibility Pack…

Patch available
Fix from $1,950 2017-11-15
Project Server HIGH 8.8
CVE-2017-11876

Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are no…

Patch available
Fix from $1,950 2017-11-15
Asp.net Core HIGH 8.8
CVE-2017-11879EPSS 7%

ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL aka "ASP…

Patch available
Fix from $1,950 2017-11-15
Excel HIGH 7.8
CVE-2017-11878EPSS 6%

Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1…

Patch available
Fix from $1,950 2017-11-15
Office HIGH 7.8
CVE-2017-11882 KEVEPSS 100%

Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an …

Patch available
Fix from $1,950 2017-11-15
Excel HIGH 7.8
CVE-2017-11884EPSS 10%

Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run arbitrary code in the context of the current user by failing to properly handle obj…

Patch available
Fix from $1,950 2017-11-15
Chakracore HIGH 7.5
CVE-2017-11858EPSS 9%

ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and …

Patch available
Fix from $1,950 2017-11-15
Chakracore HIGH 7.5
CVE-2017-11861EPSS 50%

Microsoft Edge in Windows 10 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights a…

Patch available
Fix from $1,950 2017-11-15
Chakracore HIGH 7.5
CVE-2017-11862EPSS 8%

ChakraCore and Microsoft Edge in Windows 10 1709 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user…

Patch available
Fix from $1,950 2017-11-15
Chakracore HIGH 7.5
CVE-2017-11866EPSS 8%

ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to …

Patch available
Fix from $1,950 2017-11-15
Chakracore HIGH 7.5
CVE-2017-11870EPSS 46%

ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the same user rights as the curre…

Patch available
Fix from $1,950 2017-11-15
Chakracore HIGH 7.5
CVE-2017-11871EPSS 8%

ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the same user rights as the curre…

Patch available
Fix from $1,950 2017-11-15
Chakracore HIGH 7.5
CVE-2017-11873EPSS 56%

ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain t…

Patch available
Fix from $1,950 2017-11-15
Aspnetcore HIGH 7.5
CVE-2017-11883EPSS 8%

.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by imp…

Patch available
Fix from $1,950 2017-11-15
Edge MEDIUM 6.5
CVE-2017-11872EPSS 6%

Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to force the browser to send data that would otherwise …

Patch available
Fix from $1,600 2017-11-15
Edge MEDIUM 6.1
CVE-2017-11863

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to trick…

Patch available
Fix from $1,600 2017-11-15
Windows 10 MEDIUM 5.5
CVE-2017-11853EPSS 6%

Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, a…

Patch available
Fix from $1,600 2017-11-15
Excel MEDIUM 5.5
CVE-2017-11877

Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1…

Patch available
Fix from $1,600 2017-11-15
Windows 10 HIGH 7.8
CVE-2017-11847EPSS 6%

Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 17…

Patch available
Fix from $1,950 2017-11-15
Aspnetcore HIGH 7.5
CVE-2017-11770EPSS 5%

.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by imp…

Patch available
Fix from $1,950 2017-11-15
Windows 10 HIGH 7.5
CVE-2017-11788EPSS 12%

Windows Search in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,…

Patch available
Fix from $1,950 2017-11-15
Internet Explorer HIGH 7.5
CVE-2017-11827EPSS 9%

Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft E…

Patch available
Fix from $1,950 2017-11-15
Chakracore HIGH 7.5
CVE-2017-11836EPSS 8%

ChakraCore, and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an a…

Patch available
Fix from $1,950 2017-11-15
Chakracore HIGH 7.5
CVE-2017-11837EPSS 9%

ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and …

Patch available
Fix from $1,950 2017-11-15