230 vulnerabilidades · Windows · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2009-1123
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
5.2%
2009 1 PoC

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."

CVE-2024-30051
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
43.5%
2024 CWE-122 1 PoC

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2009-4324
🔥 KEV Software Genérico Web Windows
7.8
HIGH
EPSS
92.9%
2009 2 PoCs

Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.

CVE-2017-0101
🔥 KEV Windows Windows
7.8
HIGH
EPSS
72.3%
2017 1 PoC

The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."

CVE-2022-22718
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
7.7%
2022 1 PoC

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2015-5119
🔥 KEV Software Genérico Cloud Windows
7.8
HIGH
EPSS
93.2%
2015 5 PoCs

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

CVE-2018-8174
🔥 KEV Windows 7 Windows
7.5
HIGH
EPSS
94.3%
2018 11 PoCs

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVE-2025-30397
🔥 KEV Windows 10 Version 1507 Windows
7.5
HIGH
EPSS
20.7%
2025 CWE-843 4 PoCs

Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.

CVE-2025-54313
🔥 KEV eslint-config-prettier Windows
7.5
HIGH
EPSS
11.6%
2025 CWE-506 3 PoCs

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

CVE-2020-11738
🔥 KEV Software Genérico Web Windows ⚡ nuclei
7.5
HIGH
EPSS
94.3%
2020 3 PoCs

The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.

CVE-2018-0824
🔥 KEV Software Genérico Windows
7.5
HIGH
EPSS
90.6%
2018 1 PoC

A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVE-2016-9079
🔥 KEV Firefox Windows
7.5
HIGH
EPSS
84.8%
2016 6 PoCs

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.

CVE-2021-36942
🔥 KEV Windows Server 2019 Windows
7.5
HIGH
EPSS
93.7%
2021 1 PoC

Windows LSA Spoofing Vulnerability

CVE-2017-0147
🔥 KEV Windows SMB Windows
7.5
HIGH
EPSS
92.4%
2017 6 PoCs

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."

CVE-2024-38178
🔥 KEV Windows 11 Version 24H2 Windows
7.5
HIGH
EPSS
30.2%
2024 CWE-843 1 PoC

Scripting Engine Memory Corruption Vulnerability

CVE-2018-8581
🔥 KEV Microsoft Exchange Server Windows
7.4
HIGH
EPSS
91.5%
2018 2 PoCs

An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.