imPC@ndo IT

Actively exploited vulnerabilities

770 CVE

CVE-2026-21513
Exploited High 8.8

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · and 9 more
0.15EPSS
CVE-2015-0310
Exploited High 7.8

Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Window…

adobe flash_player
0.15EPSS
CVE-2015-2360
Exploited High 8.8

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · and 5 more
0.15EPSS
CVE-2022-38028
Exploited High 7.8

Windows Print Spooler Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 9 more
0.15EPSS
CVE-2022-20708
Exploited Critical 10.0

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot…

cisco rv340_firmware · cisco rv340w_firmware · cisco rv345_firmware · cisco rv345p_firmware
0.15EPSS
CVE-2023-38180
Exploited High 7.5

.NET and Visual Studio Denial of Service Vulnerability

fedoraproject fedora · microsoft .net · microsoft asp.net_core · microsoft visual_studio_2022
0.15EPSS
CVE-2024-8069
Exploited High 8.0

Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server

citrix session_recording
0.15EPSS
CVE-2018-14634
Exploited High 7.8

An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x…

canonical ubuntu_linux · f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · and 24 more
0.15EPSS
CVE-2018-0151
Exploited Critical 9.8

A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges. The vulne…

cisco ios_xe
0.14EPSS
CVE-2017-12240
Exploited Critical 9.8

The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system. The attacker could also cause…

cisco ios
0.14EPSS
CVE-2016-0165
Exploited High 7.8

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_7 · microsoft windows_8.1 · and 4 more
0.14EPSS
CVE-2022-22948
Exploited Medium 6.5

The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.

vmware cloud_foundation · vmware vcenter_server
0.14EPSS
CVE-2025-29824
Ransomware High 7.8

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.14EPSS
CVE-2024-49039
Ransomware High 8.8

Windows Task Scheduler Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 9 more
0.14EPSS
CVE-2024-38213
Exploited Medium 6.5

Windows Mark of the Web Security Feature Bypass Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 9 more
0.14EPSS
CVE-2023-20867
Exploited Low 3.9

A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.

debian debian_linux · fedoraproject fedora · vmware tools
0.14EPSS
CVE-2025-6554
Exploited High 8.1

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

google chrome
0.13EPSS
CVE-2024-21410
Exploited Critical 9.8

Microsoft Exchange Server Elevation of Privilege Vulnerability

microsoft exchange_server
0.13EPSS
CVE-2022-20775
Exploited High 7.8

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulner…

cisco catalyst_sd-wan_manager · cisco sd-wan · cisco sd-wan_vbond_orchestrator · cisco sd-wan_vedge_cloud · and 1 more
0.12EPSS
CVE-2023-36424
Exploited High 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 10 more
0.12EPSS
CVE-2010-3904
Exploited High 7.8

The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via cr…

canonical ubuntu_linux · linux linux_kernel · opensuse opensuse · redhat enterprise_linux · and 4 more
0.12EPSS
CVE-2022-20821
Exploited Medium 6.5

A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 …

cisco ios_xr
0.12EPSS
CVE-2023-21715
Exploited High 7.3

Microsoft Publisher Security Feature Bypass Vulnerability

microsoft 365_apps
0.12EPSS
CVE-2017-11292
Exploited High 8.8

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbi…

adobe flash_player · adobe flash_player_desktop_runtime · redhat enterprise_linux_desktop · redhat enterprise_linux_server · and 1 more
0.12EPSS
CVE-2023-36033
Exploited High 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_21h2 · and 5 more
0.12EPSS