imPC@ndo IT

Actively exploited vulnerabilities

770 CVE

CVE-2016-1010
Exploited High 8.8

Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 …

adobe air · adobe air_desktop_runtime · adobe air_sdk · adobe air_sdk_\&_compiler · and 3 more
0.20EPSS
CVE-2025-7775
Exploited Critical 9.8

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC a…

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
0.20EPSS
CVE-2017-0210
Exploited High 8.8

An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Pr…

microsoft internet_explorer
0.20EPSS
CVE-2023-6345
Exploited Critical 9.6

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

debian debian_linux · fedoraproject fedora · google chrome · microsoft edge_chromium
0.19EPSS
CVE-2024-20359
Exploited Medium 6.0

A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, l…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.19EPSS
CVE-2019-1215
Ransomware High 7.8

An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1253, CVE-2019-1278, CVE-2019-1303.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · and 12 more
0.19EPSS
CVE-2019-1322
Ransomware High 7.8

An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1320, CVE-2019-1340.

microsoft windows_10_1803 · microsoft windows_10_1809 · microsoft windows_10_1903 · microsoft windows_server_1803 · and 2 more
0.19EPSS
CVE-2023-36761
Exploited Medium 6.5

Microsoft Word Information Disclosure Vulnerability

microsoft 365_apps · microsoft office · microsoft office_long_term_servicing_channel · microsoft word
0.19EPSS
CVE-2014-2120
Exploited Medium 6.1

Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025.

cisco adaptive_security_appliance_software
0.19EPSS
CVE-2016-7892
Exploited High 8.8

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.

adobe flash_player · adobe flash_player_desktop_runtime
0.19EPSS
CVE-2015-5123
Exploited Critical 9.8

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through…

adobe flash_player · adobe flash_player_desktop_runtime · opensuse evergreen · redhat enterprise_linux_desktop · and 5 more
0.18EPSS
CVE-2022-22718
Exploited High 7.8

Windows Print Spooler Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · and 13 more
0.18EPSS
CVE-2019-5591
Exploited Medium 6.5

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

fortinet fortios
0.18EPSS
CVE-2018-8440
Ransomware High 7.8

An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Serve…

microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · microsoft windows_10_1803 · and 6 more
0.18EPSS
CVE-2024-7965
Exploited High 8.8

Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

google chrome · microsoft edge_chromium
0.18EPSS
CVE-2018-0147
Exploited Critical 9.8

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure dese…

cisco secure_access_control_system
0.18EPSS
CVE-2017-0022
Exploited Medium 6.5

Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in me…

microsoft windows_8.1 · microsoft windows_server_2008 · microsoft windows_server_2012 · microsoft xml_core_services
0.18EPSS
CVE-2026-22719
Exploited High 8.1

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration…

vmware aria_operations · vmware cloud_foundation · vmware telco_cloud_infrastructure · vmware telco_cloud_platform
0.17EPSS
CVE-2024-38813
Exploited High 7.5

The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.

vmware cloud_foundation · vmware vcenter_server
0.17EPSS
CVE-2022-22047
Exploited High 7.8

Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 12 more
0.17EPSS
CVE-2023-36036
Exploited High 7.8

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 9 more
0.17EPSS
CVE-2021-20022
Ransomware High 7.2

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

sonicwall email_security · sonicwall email_security_appliance_3300_firmware · sonicwall email_security_appliance_4300_firmware · sonicwall email_security_appliance_5000_firmware · and 7 more
0.17EPSS
CVE-2020-0986
Exploited High 7.8

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264,…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · and 13 more
0.16EPSS
CVE-2024-20481
Exploited Medium 5.8

A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN servi…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.16EPSS
CVE-2023-35311
Exploited High 8.8

Microsoft Outlook Security Feature Bypass Vulnerability

microsoft 365_apps · microsoft office · microsoft office_long_term_servicing_channel · microsoft outlook
0.16EPSS