cbcvebase.

Microsoft Windows 7 vulnerabilities

906 known vulnerabilities affecting microsoft/windows_7.

Total CVEs
906
CISA KEV
36
actively exploited
Public exploits
47
Exploited in wild
53
Severity breakdown
CRITICAL26HIGH674MEDIUM204LOW2

Vulnerabilities

Page 7 of 46
CVE-2020-1112P3CRITICALCVSS 9.9≥ 6.1.0, < publication2020-05-21
CVE-2020-1112 [CRITICAL] CWE-434 CVE-2020-1112: An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Serv An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content. An attacker who successfully exploited this vulnerability could upload restricted file types to an IIS-hosted folder. To exploit this vulnerability, an attacker would require permissions to up
nvd
CVE-2021-43215P3CRITICALCVSS 9.8≥ 6.1.0, < 6.1.7601.257962021-12-15
CVE-2021-43215 [CRITICAL] CWE-787 CVE-2021-43215: iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution
nvd
CVE-2021-1666P3HIGHCVSS 8.8≥ 6.1.0, < publication2021-01-12
CVE-2021-1666 [HIGH] CVE-2021-1666: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-1658P3HIGHCVSS 8.8≥ 6.1.0, < publication2021-01-12
CVE-2021-1658 [HIGH] CVE-2021-1658: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-1660P3HIGHCVSS 8.8≥ 6.1.0, < publication2021-01-12
CVE-2021-1660 [HIGH] CVE-2021-1660: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-1664P3HIGHCVSS 8.8≥ 6.1.0, < publication2021-01-12
CVE-2021-1664 [HIGH] CVE-2021-1664: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-1671P3HIGHCVSS 8.8≥ 6.1.0, < publication2021-01-12
CVE-2021-1671 [HIGH] CVE-2021-1671: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-1673P3HIGHCVSS 8.8≥ 6.1.0, < publication2021-01-12
CVE-2021-1673 [HIGH] CVE-2021-1673: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-26881P3HIGHCVSS 8.8≥ 6.1.0, < 6.1.7601.245662021-03-11
CVE-2021-26881 [HIGH] CVE-2021-26881: Microsoft Windows Media Foundation Remote Code Execution Vulnerability Microsoft Windows Media Foundation Remote Code Execution Vulnerability
nvd
CVE-2021-31194P3HIGHCVSS 8.8≥ 6.1.0, < 6.1.7601.24597≥ 6.1.0, < 6.1.7601.245982021-05-11
CVE-2021-31194 [HIGH] CVE-2021-31194: OLE Automation Remote Code Execution Vulnerability OLE Automation Remote Code Execution Vulnerability
nvd
CVE-2021-42275P3HIGHCVSS 8.8≥ 6.1.0, < 6.1.7601.257692021-11-10
CVE-2021-42275 [HIGH] CVE-2021-42275: Microsoft COM for Windows Remote Code Execution Vulnerability Microsoft COM for Windows Remote Code Execution Vulnerability
nvd
CVE-2018-8423P3HIGHCVSS 7.8v32-bit Systems Service Pack 1vx64-based Systems Service Pack 12018-10-10
CVE-2018-8423 [HIGH] CWE-119 CVE-2018-8423: A remote code execution vulnerability exists in the Microsoft JET Database Engine, aka "Microsoft JE A remote code execution vulnerability exists in the Microsoft JET Database Engine, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Wi
nvd
CVE-2019-0888P3HIGHCVSS 8.8≥ 6.1.0, < publication2019-06-12
CVE-2019-0888 [HIGH] CVE-2019-0888: A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objec A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with the victim user’s privileges. An attacker could craft a website that exploits the vulnerability and then convince a victim user to visit the website. The secu
nvd
CVE-2020-17042P3HIGHCVSS 8.8≥ 6.1.0, < publication2020-11-11
CVE-2020-17042 [HIGH] CVE-2020-17042: Windows Print Spooler Remote Code Execution Vulnerability Windows Print Spooler Remote Code Execution Vulnerability
nvd
CVE-2021-1674P3HIGHCVSS 8.8≥ 6.1.0, < publication2021-01-12
CVE-2021-1674 [HIGH] CVE-2021-1674: Windows Remote Desktop Protocol Core Security Feature Bypass Vulnerability Windows Remote Desktop Protocol Core Security Feature Bypass Vulnerability
nvd
CVE-2022-21922P3HIGHCVSS 8.8≥ 6.1.0, < 6.1.7601.258292022-01-11
CVE-2022-21922 [HIGH] CVE-2022-21922: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28327P3HIGHCVSS 8.8≥ 6.1.0, < publication2021-04-13
CVE-2021-28327 [HIGH] CVE-2021-28327: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28340P3HIGHCVSS 8.8≥ 6.1.0, < publication2021-04-13
CVE-2021-28340 [HIGH] CVE-2021-28340: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28356P3HIGHCVSS 8.8≥ 6.1.0, < publication2021-04-13
CVE-2021-28356 [HIGH] CVE-2021-28356: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28344P3HIGHCVSS 8.8≥ 6.1.0, < publication2021-04-13
CVE-2021-28344 [HIGH] CVE-2021-28344: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
Microsoft Windows 7 vulnerabilities | cvebase