1074 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2021-43226
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
8.4%
2021 1 PoC

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2016-0185
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
80.2%
2016 1 PoC

Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Execution Vulnerability."

CVE-2009-1123
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
5.2%
2009 1 PoC

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."

CVE-2009-0557
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
86.4%
2009 1 PoC

Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Object Record Corruption Vulnerability."

CVE-2025-60710
🔥 KEV Windows 11 Version 24H2 Windows
7.8
HIGH
EPSS
29.7%
2025 CWE-59 2 PoCs

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

CVE-2009-3129
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
91.2%
2009 1 PoC

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset, aka "Excel Featheader Record Memory Corruption Vulnerability."

CVE-2009-1862
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
58.6%
2009 3 PoCs

Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.

CVE-2009-0563
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
79.9%
2009 1 PoC

Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a crafted tag containing an invalid length field, aka "Word Buffer Overflow Vulnerability."

CVE-2026-33825
🔥 KEV Microsoft Defender Antimalware Platform General
7.8
HIGH
EPSS
4.9%
2026 CWE-1220 1 PoC

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

CVE-2009-4324
🔥 KEV Software Genérico Web Windows
7.8
HIGH
EPSS
92.9%
2009 2 PoCs

Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.

CVE-2008-2992
🔥 KEV Software Genérico Web
7.8
HIGH
EPSS
93.7%
2008 4 PoCs

Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.

CVE-2026-21533
🔥 KEV Windows 10 Version 1607 Windows
7.8
HIGH
EPSS
20.2%
2026 CWE-269 2 PoCs

Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

CVE-2024-1086
🔥 KEV Kernel General
7.8
HIGH
EPSS
84.7%
2024 CWE-416 12 PoCs

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, and hence the nf_hook_slow() function can cause a double free vulnerability when NF_DROP is issued with a drop error which resembles NF_ACCEPT. We recommend upgrading past commit f342de4e2f33e0e39165d8639387aa6c19dff660.

CVE-2024-30051
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
43.5%
2024 CWE-122 1 PoC

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2017-0101
🔥 KEV Windows Windows
7.8
HIGH
EPSS
72.3%
2017 1 PoC

The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."

CVE-2016-7255
🔥 KEV Software Genérico Windows
7.8
HIGH
EPSS
89.4%
2016 10 PoCs

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

CVE-2023-29336
🔥 KEV Windows 10 Version 1507 Windows
7.8
HIGH
EPSS
79.5%
2023 CWE-416 2 PoCs

Win32k Elevation of Privilege Vulnerability

CVE-2017-11882
🔥 KEV Microsoft Office General
7.8
HIGH
EPSS
94.4%
2017 37 PoCs

Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11884.

CVE-2014-3153
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
68.9%
2014 6 PoCs

The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.

CVE-2017-0261
🔥 KEV Microsoft Office General
7.8
HIGH
EPSS
92.3%
2017 2 PoCs

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0262 and CVE-2017-0281.