Записи Microsoft
27 264 опубликованных записей вендора microsoft.
Профиль для исследователя
- Попали в KEV
- 494 · 1,8 %
- С эксплойтом
- 726 · 2,7 %
- Pre-auth RCE
- 6 692
- С записью об исправлении
- 22 %
- Медиана: публикация → KEV
- 645 дн.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2 341
- CWE-416 Use After Free2 337
- CWE-125 Out-of-bounds Read1 730
- CWE-787 Out-of-bounds Write1 471
- CWE-20 Improper Input Validation1 304
- CWE-122 Heap-based Buffer Overflow1 264
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 000+ записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2020-0796Готовый эксплойт | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requemicrosoft · windows 10 1903 · CWE-119 | Критическая10,0 | KEV | 99,8 % | 12 мар. 2020 г. |
99Срочно | CVE-2019-0708Готовый эксплойт | A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attackermicrosoft · windows 7 · CWE-416 | Критическая9,8 | KEV | 100,0 % | 16 мая 2019 г. |
99Срочно | CVE-2015-1635Готовый эксплойт | HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote amicrosoft · windows 7 · CWE-94 | Критическая9,8 | KEV | 100,0 % | 14 апр. 2015 г. |
99Срочно | CVE-2013-2251Готовый эксплойт | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,apache · archiva · CWE-74 | Критическая9,8 | KEV | 100,0 % | 19 июл. 2013 г. |
99Срочно | CVE-2025-53770Готовый эксплойт | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-502 | Критическая9,8 | KEV | 100,0 % | 19 июл. 2025 г. |
99Срочно | CVE-2024-4577Готовый эксплойт | Argument Injection in PHP-CGIphp · php · CWE-78 | Критическая9,8 | KEV | 100,0 % | 9 июн. 2024 г. |
99Срочно | CVE-2023-29357Готовый эксплойт | Microsoft SharePoint Server Elevation of Privilege Vulnerabilitymicrosoft · sharepoint server · CWE-303 | Критическая9,8 | KEV | 100,0 % | 13 июн. 2023 г. |
99Срочно | CVE-2025-59287Готовый эксплойт | Windows Server Update Service (WSUS) Remote Code Execution Vulnerabilitymicrosoft · windows server 2012 · CWE-502 | Критическая9,8 | KEV | 100,0 % | 14 окт. 2025 г. |
99Срочно | CVE-2022-47986Готовый эксплойт | IBM Aspera Faspex code executionibm · aspera faspex · CWE-502 | Критическая9,8 | KEV | 100,0 % | 17 февр. 2023 г. |
99Срочно | CVE-2015-3113Готовый эксплойт | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Критическая9,8 | KEV | 99,9 % | 23 июн. 2015 г. |
99Срочно | CVE-2021-38647Готовый эксплойт | Open Management Infrastructure (OMI) Remote Code Execution Vulnerabilitymicrosoft · azure automation state configuration | Критическая9,8 | KEV | 99,9 % | 15 сент. 2021 г. |
99Срочно | CVE-2019-0604Готовый эксплойт | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application pamicrosoft · sharepoint enterprise server · CWE-20 | Критическая9,8 | KEV | 99,9 % | 5 мар. 2019 г. |
99Срочно | CVE-2014-0497Готовый эксплойт | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1adobe · flash player · CWE-191 | Критическая9,8 | KEV | 99,9 % | 5 февр. 2014 г. |
99Срочно | CVE-2021-31166Готовый эксплойт | HTTP Protocol Stack Remote Code Execution Vulnerabilitymicrosoft · windows 10 2004 · CWE-416 | Критическая9,8 | KEV | 99,9 % | 11 мая 2021 г. |
99Срочно | CVE-2017-7269Готовый эксплойт | Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Smicrosoft · internet information services · CWE-120 | Критическая9,8 | KEV | 99,8 % | 26 мар. 2017 г. |
99Срочно | CVE-2015-5119Готовый эксплойт | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296adobe · flash player · CWE-416 | Критическая9,8 | KEV | 99,3 % | 8 июл. 2015 г. |
99Срочно | CVE-2020-0646Готовый эксплойт | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote microsoft · .net framework · CWE-91 | Критическая9,8 | KEV | 99,2 % | 14 янв. 2020 г. |
99Срочно | CVE-2008-4250Готовый эксплойт | The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta amicrosoft · windows 2000 · CWE-94 | Критическая9,8 | KEV | 98,8 % | 23 окт. 2008 г. |
99Срочно | CVE-2020-1350Готовый эксплойт | A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows microsoft · windows server 2008 · CWE-20 | Критическая10,0 | KEV | 96,7 % | 14 июл. 2020 г. |
98Срочно | CVE-2023-23397Готовый эксплойт | Microsoft Outlook Elevation of Privilege Vulnerabilitymicrosoft · 365 apps · CWE-20 | Критическая9,8 | KEV | 97,2 % | 14 мар. 2023 г. |
98Срочно | CVE-2015-0313Готовый эксплойт | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before adobe · flash player · CWE-416 | Критическая9,8 | KEV | 95,3 % | 2 февр. 2015 г. |
97Срочно | CVE-2024-21413Готовый эксплойт | Microsoft Outlook Remote Code Execution Vulnerabilitymicrosoft · 365 apps · CWE-20 | Критическая9,8 | KEV | 94,7 % | 13 февр. 2024 г. |
97Срочно | CVE-2015-5122Готовый эксплойт | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0adobe · flash player · CWE-416 | Критическая9,8 | KEV | 94,0 % | 14 июл. 2015 г. |
97Срочно | CVE-2013-0625Готовый эксплойт | Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exeadobe · coldfusion · CWE-287 | Критическая9,8 | KEV | 93,8 % | 8 янв. 2013 г. |
96Срочно | CVE-2021-34473Готовый эксплойт | Microsoft Exchange Server Remote Code Execution Vulnerabilitymicrosoft · exchange server · CWE-918 | Критическая9,1 | KEV | 100,0 % | 14 июл. 2021 г. |
- CVE-2020-0796100Срочно
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain reque
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %microsoft · windows 10 190312 мар. 2020 г.
- CVE-2019-070899Срочно
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · windows 716 мая 2019 г.
- CVE-2015-163599Срочно
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · windows 714 апр. 2015 г.
- CVE-2013-225199Срочно
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · archiva19 июл. 2013 г.
- CVE-2025-5377099Срочно
Microsoft SharePoint Server Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · sharepoint server19 июл. 2025 г.
- CVE-2024-457799Срочно
Argument Injection in PHP-CGI
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php9 июн. 2024 г.
- CVE-2023-2935799Срочно
Microsoft SharePoint Server Elevation of Privilege Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · sharepoint server13 июн. 2023 г.
- CVE-2025-5928799Срочно
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · windows server 201214 окт. 2025 г.
- CVE-2022-4798699Срочно
IBM Aspera Faspex code execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %ibm · aspera faspex17 февр. 2023 г.
- CVE-2015-311399Срочно
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · flash player23 июн. 2015 г.
- CVE-2021-3864799Срочно
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · azure automation state configuration15 сент. 2021 г.
- CVE-2019-060499Срочно
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application pa
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · sharepoint enterprise server5 мар. 2019 г.
- CVE-2014-049799Срочно
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · flash player5 февр. 2014 г.
- CVE-2021-3116699Срочно
HTTP Protocol Stack Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · windows 10 200411 мая 2021 г.
- CVE-2017-726999Срочно
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows S
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · internet information services26 мар. 2017 г.
- CVE-2015-511999Срочно
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %adobe · flash player8 июл. 2015 г.
- CVE-2020-064699Срочно
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %microsoft · .net framework14 янв. 2020 г.
- CVE-2008-425099Срочно
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %microsoft · windows 200023 окт. 2008 г.
- CVE-2020-135099Срочно
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 97 %microsoft · windows server 200814 июл. 2020 г.
- CVE-2023-2339798Срочно
Microsoft Outlook Elevation of Privilege Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %microsoft · 365 apps14 мар. 2023 г.
- CVE-2015-031398Срочно
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %adobe · flash player2 февр. 2015 г.
- CVE-2024-2141397Срочно
Microsoft Outlook Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %microsoft · 365 apps13 февр. 2024 г.
- CVE-2015-512297Срочно
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %adobe · flash player14 июл. 2015 г.
- CVE-2013-062597Срочно
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly exe
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %adobe · coldfusion8 янв. 2013 г.
- CVE-2021-3447396Срочно
Microsoft Exchange Server Remote Code Execution Vulnerability
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 100 %microsoft · exchange server14 июл. 2021 г.