16 vulnerabilidades · Windows · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2024-4577
🔥 KEV PHP Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2024 CWE-78 85 PoCs

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

CVE-2024-21410
🔥 KEV Microsoft Exchange Server 2016 Cumulative Update 23 Windows
9.8
CRITICAL
EPSS
5.5%
2024 CWE-287 2 PoCs

Microsoft Exchange Server Elevation of Privilege Vulnerability

CVE-2024-29988
🔥 KEV Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
60.5%
2024 CWE-693 2 PoCs

SmartScreen Prompt Security Feature Bypass Vulnerability

CVE-2024-49039
🔥 KEV Windows Server 2025 Windows
8.8
HIGH
EPSS
63.7%
2024 CWE-287 2 PoCs

Windows Task Scheduler Elevation of Privilege Vulnerability

CVE-2024-21412
🔥 KEV Windows 11 version 21H2 Windows
8.1
HIGH
EPSS
93.8%
2024 CWE-693 2 PoCs

Internet Shortcut Files Security Feature Bypass Vulnerability

CVE-2024-38193
🔥 KEV Windows 11 Version 24H2 Windows
7.8
HIGH
EPSS
73.2%
2024 CWE-416 2 PoCs

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2024-38080
🔥 KEV Windows Server 2022 Windows
7.8
HIGH
EPSS
13.7%
2024 CWE-190 1 PoC

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2024-30051
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
43.5%
2024 CWE-122 1 PoC

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2024-38178
🔥 KEV Windows 11 Version 24H2 Windows
7.5
HIGH
EPSS
30.2%
2024 CWE-843 1 PoC

Scripting Engine Memory Corruption Vulnerability

CVE-2024-37085
🔥 KEV VMware ESXi Web Windows
6.8
MEDIUM
EPSS
75.1%
2024 4 PoCs

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

CVE-2024-43451
🔥 KEV Windows Server 2025 Windows
6.5
MEDIUM
EPSS
90.3%
2024 CWE-73 1 PoC

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2024-38217
🔥 KEV Windows 10 Version 1809 Windows
5.4
MEDIUM
EPSS
12.1%
2024 CWE-693 1 PoC

Windows Mark of the Web Security Feature Bypass Vulnerability