11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2023-29532
Firefox Windows
5.5
MEDIUM
EPSS
0.1%
2023 1 PoC

A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.

CVE-2021-1116
NVIDIA GPU Display Driver Windows
5.5
MEDIUM
EPSS
0.0%
2021 CWE-476 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a NULL pointer dereference in the kernel, created within user mode code, may lead to a denial of service in the form of a system crash.

CVE-2021-1096
NVIDIA GPU Display Driver Windows
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

NVIDIA Windows GPU Display Driver for Windows contains a vulnerability in the NVIDIA kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where dereferencing a NULL pointer may lead to a system crash.

CVE-2021-36873
iQ Block Country Web Windows ⚡ nuclei
5.5
MEDIUM
EPSS
1.8%
2021 CWE-79 0 PoCs

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.11). Vulnerable parameter: &blockcountry_blockmessage.

CVE-2023-31022
NVIDIA GPU Display driver, vGPU driver, and Cloud gaming driver Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2023 CWE-476 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a NULL-pointer dereference may lead to denial of service.

CVE-2020-1472
🔥 KEV Windows Server version 2004 Windows
5.5
MEDIUM
EPSS
94.4%
2020 59 PoCs

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by

CVE-2013-3900
🔥 KEV Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
74.4%
2013 CWE-347 12 PoCs

Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows 11. While the format is different from the original CVE published in 2013, except for clarifications about how to configure the EnableCertPaddingCheck registry value, the information herein remains unchanged from the original text published on December 10, 2013, Microsoft does not plan to enforce the stricter verificatio

CVE-2021-38926
DB2 for Linux, UNIX and Windows Windows
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 210321.

CVE-2021-24098
Windows 10 Version 2004 Windows
5.5
MEDIUM
EPSS
2.0%
2021 1 PoC

Windows Console Driver Denial of Service Vulnerability

CVE-2021-1656
Windows 10 Version 20H2 Windows
5.5
MEDIUM
EPSS
1.7%
2021 1 PoC

TPM Device Driver Information Disclosure Vulnerability

CVE-2021-24084
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
4.0%
2021 2 PoCs

Windows Mobile Device Management Information Disclosure Vulnerability

CVE-2023-36576
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
0.5%
2023 CWE-190 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2021-34496
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
2.4%
2021 1 PoC

Windows GDI Information Disclosure Vulnerability

CVE-2021-31970
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
0.8%
2021 1 PoC

Windows TCP/IP Driver Security Feature Bypass Vulnerability

CVE-2023-38140
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
0.2%
2023 CWE-908 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2023-28271
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
0.4%
2023 CWE-200 1 PoC

Windows Kernel Memory Information Disclosure Vulnerability

CVE-2021-33602
F-Secure endpoint protection products on Windows and Mac. F-Secure Linux Security (32-bit) F-Secure Linux Security 64 F-Secure Atlant & F-Secure Cloud Protection for Salesforce Cloud Windows
5.5
MEDIUM
EPSS
0.3%
2021 1 PoC

A vulnerability affecting the F-Secure Antivirus engine was discovered when the engine tries to unpack a zip archive (LZW decompression method), and this can crash the scanning engine. The vulnerability can be exploited remotely by an attacker. A successful attack will result in Denial-of-Service of the Anti-Virus engine.

CVE-2021-1699
Windows 10 Version 20H2 Windows
5.5
MEDIUM
EPSS
0.8%
2021 1 PoC

Windows (modem.sys) Information Disclosure Vulnerability

CVE-2020-11042
FreeRDP Windows
5.5
MEDIUM
EPSS
0.1%
2020 CWE-125 1 PoC

In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading a attacker-defined amount of client memory (32bit unsigned -> 4GB) to an intermediate buffer. This can be used to crash the client or store information for later retrieval. This has been patched in 2.0.0.

CVE-2019-1148
Windows 10 Version 1703 Windows
5.5
MEDIUM
EPSS
4.2%
2019 1 PoC

An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The update addresses the vulnerability by correcting the way in which the Windows Graphics Component handles objects in memory.