Vulnerabilities > Microsoft > High

DATE CVE VULNERABILITY TITLE RISK
2024-09-10 CVE-2024-43474 Unspecified vulnerability in Microsoft SQL Server 2017 and SQL Server 2019
Microsoft SQL Server Information Disclosure Vulnerability
network
low complexity
microsoft
7.5
2024-09-10 CVE-2024-43475 Unspecified vulnerability in Microsoft Windows Server 2008
Microsoft Windows Admin Center Information Disclosure Vulnerability
network
low complexity
microsoft
7.3
2024-09-10 CVE-2024-43479 Unspecified vulnerability in Microsoft Power Automate
Microsoft Power Automate Desktop Remote Code Execution Vulnerability
network
high complexity
microsoft
8.5
2024-09-10 CVE-2024-43492 Unspecified vulnerability in Microsoft Autoupdate
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
local
low complexity
microsoft
7.8
2024-09-10 CVE-2024-43495 Unspecified vulnerability in Microsoft Windows 11 22H2
Windows libarchive Remote Code Execution Vulnerability
local
low complexity
microsoft
7.3
2024-08-26 CVE-2024-41879 Out-of-bounds Write vulnerability in multiple products
Acrobat Reader versions 127.0.2651.105 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.
local
low complexity
adobe microsoft CWE-787
7.8
2024-08-22 CVE-2024-38209 Type Confusion vulnerability in Microsoft Edge Chromium
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
local
low complexity
microsoft CWE-843
7.8
2024-08-22 CVE-2024-38210 Out-of-bounds Read vulnerability in Microsoft Edge Chromium
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
local
low complexity
microsoft CWE-125
7.8
2024-08-21 CVE-2024-7965 Out-of-bounds Write vulnerability in multiple products
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google microsoft CWE-787
8.8
2024-08-20 CVE-2024-38175 Unspecified vulnerability in Microsoft Azure Managed Instance for Apache Cassandra
An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.
network
low complexity
microsoft
8.8