4628 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2019-1405
🔥 KEV Windows Windows
7.8
HIGH
EPSS
53.9%
2019 1 PoC

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.

CVE-2019-0859
🔥 KEV Windows Windows
7.8
HIGH
EPSS
10.6%
2019 1 PoC

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803.

CVE-2019-0808
🔥 KEV Windows Windows
7.8
HIGH
EPSS
74.0%
2019 6 PoCs

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0797.

CVE-2019-1253
🔥 KEV Windows Windows
7.8
HIGH
EPSS
31.9%
2019 6 PoCs

An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1278, CVE-2019-1303.

CVE-2019-0543
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
24.5%
2019 1 PoC

An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVE-2019-1315
🔥 KEV Windows Windows
7.8
HIGH
EPSS
7.6%
2019 1 PoC

An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1339, CVE-2019-1342.

CVE-2019-1215
🔥 KEV Windows Windows
7.8
HIGH
EPSS
5.2%
2019 1 PoC

An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1253, CVE-2019-1278, CVE-2019-1303.

CVE-2019-1322
🔥 KEV Windows Windows
7.8
HIGH
EPSS
36.5%
2019 1 PoC

An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1320, CVE-2019-1340.

CVE-2021-34486
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
36.5%
2021 2 PoCs

Windows Event Tracing Elevation of Privilege Vulnerability

CVE-2021-27086
Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Windows Services and Controller App Elevation of Privilege Vulnerability

CVE-2021-23887
McAfee Data Loss Prevention (DLP) Endpoint for Windows Windows
7.8
HIGH
EPSS
0.0%
2021 CWE-269 2 PoCs

Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to write to arbitrary controlled kernel addresses. This is achieved by launching applications, suspending them, modifying the memory and restarting them when they are monitored by McAfee DLP through the hdlphook driver.

CVE-2021-31168
Windows 10 Version 2004 DevOps Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2021-28313
Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
0.5%
2021 2 PoCs

Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability

CVE-2021-1089
NVIDIA GPU Display Driver Windows
7.8
HIGH
EPSS
0.1%
2021 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in nvidia-smi where an uncontrolled DLL loading path may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

CVE-2021-33542
Automation Worx Software Suite Windows
7.8
HIGH
EPSS
0.5%
2021 CWE-824 1 PoC

Phoenix Contact Classic Automation Worx Software Suite in Version 1.87 and below is affected by a remote code execution vulnerability. Manipulated PC Worx or Config+ projects could lead to a remote code execution when unallocated memory is freed because of incompletely initialized data. The attacker needs to get access to an original bus configuration file (*.bcp) to be able to manipulate data inside. After manipulation the attacker needs to exchange the original file by the manipulated one on the application programming workstation. Availability, integrity, or confidentiality of an applicatio

CVE-2021-26415
Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
11.5%
2021 1 PoC

Windows Installer Elevation of Privilege Vulnerability