2040 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-38141
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.3%
2023 CWE-367 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-29343
Windows Sysmon Windows
7.8
HIGH
EPSS
15.6%
2023 CWE-59 1 PoC

SysInternals Sysmon for Windows Elevation of Privilege Vulnerability

CVE-2023-20178
Cisco Secure Client Networking Windows
7.8
HIGH
EPSS
27.7%
2023 CWE-276 3 PoCs

A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The client update process is executed after a successful VPN connection is established. This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the update process. An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process. A succe

CVE-2023-3513
Razer Central Windows
7.8
HIGH
EPSS
0.1%
2023 CWE-269 1 PoC

Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access to gain SYSTEM privilege via communicating with the named pipe as a low-privilege user and triggering an insecure .NET deserialization.

CVE-2023-21823
🔥 KEV Microsoft Office for Android Windows
7.8
HIGH
EPSS
5.0%
2023 CWE-190 1 PoC

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2023-38154
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.2%
2023 CWE-122 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-35841
WinFlash Driver Windows
7.8
HIGH
EPSS
0.2%
2023 CWE-732 1 PoC

Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.

CVE-2023-23423
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.1%
2023 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-36900
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
24.0%
2023 CWE-190 1 PoC

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-36723
Windows 10 Version 1809 DevOps Windows
7.8
HIGH
EPSS
7.5%
2023 CWE-59 1 PoC

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2023-35386
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
2.4%
2023 CWE-125 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-21748
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.5%
2023 2 PoCs

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-23416
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
3.2%
2023 CWE-20 1 PoC

Windows Cryptographic Services Remote Code Execution Vulnerability

CVE-2024-43583
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
3.7%
2024 CWE-250 2 PoCs

Winlogon Elevation of Privilege Vulnerability

CVE-2024-0120
GPU, vGPU, and Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.2%
2024 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-22002
Software Genérico Windows
7.8
HIGH
EPSS
2.4%
2024 1 PoC

CORSAIR iCUE 5.9.105 with iCUE Murals on Windows allows unprivileged users to insert DLL files in the cuepkg-1.2.6 subdirectory of the installation directory.

CVE-2024-23773
Software Genérico Windows
7.8
HIGH
EPSS
0.3%
2024 1 PoC

An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file delete vulnerability exists in the KSchedulerSvc.exe component. Local attackers can delete any file of their choice with NT Authority\SYSTEM privileges.

CVE-2024-0197
Sentinel HASP LDK Windows
7.8
HIGH
EPSS
1.6%
2024 CWE-269 1 PoC

A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate their privilege level via local access.