imPC@ndo IT

Actively exploited vulnerabilities

770 CVE

CVE-2022-40684
Ransomware Critical 9.8

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an una…

fortinet fortios · fortinet fortiproxy · fortinet fortiswitchmanager
1.00EPSS
CVE-2024-45195
Exploited High 7.5

Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

apache ofbiz
1.00EPSS
CVE-2025-53770
Ransomware Critical 9.8

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a co…

microsoft sharepoint_server
1.00EPSS
CVE-2021-45046
Ransomware Critical 9.0

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default…

apache log4j · cvat computer_vision_annotation_tool · debian debian_linux · fedoraproject fedora · and 51 more
1.00EPSS
CVE-2022-41082
Ransomware High 8.0

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2012-0158
Exploited High 8.8

The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2…

microsoft biztalk_server · microsoft commerce_server · microsoft commerce_server_2009 · microsoft office · and 6 more
1.00EPSS
CVE-2022-47986
Ransomware Critical 9.8

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to ex…

ibm aspera_faspex
1.00EPSS
CVE-2020-0688
Ransomware High 8.8

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.

microsoft exchange_server
1.00EPSS
CVE-2021-42013
Ransomware Critical 9.8

It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories ar…

apache http_server · fedoraproject fedora · netapp cloud_backup · oracle instantis_enterprisetrack · and 2 more
1.00EPSS
CVE-2025-5777
Ransomware High 7.5

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
1.00EPSS
CVE-2022-1388
Ransomware Critical 9.8

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Softw…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · f5 big-ip_application_acceleration_manager · and 7 more
1.00EPSS
CVE-2024-38475
Exploited Critical 9.1

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code …

apache http_server · netapp ontap_9 · sonicwall sma_200_firmware · sonicwall sma_210_firmware · and 3 more
1.00EPSS
CVE-2022-41040
Ransomware High 8.8

Microsoft Exchange Server Elevation of Privilege Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2021-27065
Ransomware High 7.8

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
1.00EPSS
CVE-2017-11882
Ransomware High 7.8

Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memo…

microsoft office
1.00EPSS
CVE-2015-3113
Exploited Critical 9.8

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild …

adobe flash_player · hp insight_orchestration · hp system_management_homepage · hp systems_insight_manager · and 11 more
1.00EPSS
CVE-2014-7169
Exploited Critical 9.8

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as …

apple mac_os_x · arista eos · canonical ubuntu_linux · checkpoint security_gateway · and 70 more
1.00EPSS
CVE-2022-22963
Exploited Critical 9.8

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local r…

oracle banking_branch · oracle banking_cash_management · oracle banking_corporate_lending_process_management · oracle banking_credit_facilities_process_management · and 24 more
1.00EPSS
CVE-2025-59287
Exploited Critical 9.8

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019 · microsoft windows_server_2022 · and 2 more
1.00EPSS
CVE-2021-38647
Ransomware Critical 9.8

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

microsoft azure_automation_state_configuration · microsoft azure_automation_update_management · microsoft azure_diagnostics_\(lad\) · microsoft azure_security_center · and 6 more
1.00EPSS
CVE-2017-0199
Ransomware High 7.8

Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, ak…

microsoft office · microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_server_2012 · and 2 more
1.00EPSS
CVE-2021-1497
Exploited Critical 9.8

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Deta…

cisco hyperflex_hx_data_platform
1.00EPSS
CVE-2025-24813
Exploited Critical 9.8

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 t…

apache tomcat · debian debian_linux · netapp bootstrap_os
1.00EPSS
CVE-2025-49704
Ransomware High 8.8

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

microsoft sharepoint_server
1.00EPSS
CVE-2026-31431
Exploited High 7.8

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in alg…

amazon amazon_linux · arista cloudvision_agni · arista cloudvision_portal · arista netvisor_os · and 39 more
1.00EPSS