imPC@ndo IT

Actively exploited vulnerabilities

770 CVE

CVE-2019-0676
Exploited Medium 6.5

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vul…

microsoft internet_explorer
0.08EPSS
CVE-2022-24521
Ransomware High 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · and 13 more
0.07EPSS
CVE-2020-3950
Exploited High 7.8

VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitatio…

vmware fusion · vmware horizon_client · vmware remote_console
0.07EPSS
CVE-2018-0158
Exploited High 8.6

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (Do…

cisco ios · cisco ios_xe
0.07EPSS
CVE-2004-0210
Exploited High 7.8

The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.

microsoft interix · microsoft windows_2000 · microsoft windows_nt
0.07EPSS
CVE-2017-6744
Exploited High 8.8

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. …

cisco ios
0.07EPSS
CVE-2017-12237
Exploited High 7.5

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected…

cisco ios · cisco ios_xe
0.07EPSS
CVE-2017-12235
Exploited High 7.5

A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) co…

cisco ios
0.07EPSS
CVE-2017-12234
Exploited High 7.5

Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) conditio…

cisco ios
0.07EPSS
CVE-2017-12233
Exploited High 7.5

Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) conditio…

cisco ios
0.07EPSS
CVE-2017-12231
Exploited High 7.5

A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due…

cisco ios
0.07EPSS
CVE-2018-0154
Exploited High 7.5

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is d…

cisco ios
0.07EPSS
CVE-2024-38080
Exploited High 7.8

Windows Hyper-V Elevation of Privilege Vulnerability

microsoft windows_11_21h2 · microsoft windows_11_22h2 · microsoft windows_11_23h2 · microsoft windows_server_2022 · and 1 more
0.07EPSS
CVE-2026-34621
Exploited High 8.6

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the curren…

adobe acrobat · adobe acrobat_dc · adobe acrobat_reader_dc
0.07EPSS
CVE-2023-26369
Exploited High 7.8

Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of…

adobe acrobat · adobe acrobat_dc · adobe acrobat_reader · adobe acrobat_reader_dc
0.07EPSS
CVE-2026-20128
Exploited High 7.5

A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain DCA user privileges on an affected system. This vulnerability is due to the presence of a credential file for…

cisco catalyst_sd-wan_manager
0.07EPSS
CVE-2018-0159
Exploited High 7.5

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of servi…

cisco ios · cisco ios_xe
0.07EPSS
CVE-2020-1040
Exploited Critical 9.0

A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is un…

microsoft windows_server_2008 · microsoft windows_server_2012 · microsoft windows_server_2016
0.07EPSS
CVE-2019-1064
Ransomware High 7.8

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install pr…

microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · microsoft windows_10_1803 · and 7 more
0.07EPSS
CVE-2022-27518
Exploited Critical 9.8

Unauthenticated remote arbitrary code execution

citrix application_delivery_controller_firmware · citrix gateway_firmware
0.07EPSS
CVE-2026-33825
Ransomware High 7.8

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

microsoft defender_antimalware_platform
0.07EPSS
CVE-2012-0767
Exploited Medium 6.1

Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to in…

adobe flash_player
0.07EPSS
CVE-2021-33739
Exploited High 8.4

Microsoft DWM Core Library Elevation of Privilege Vulnerability

microsoft windows_10_1909 · microsoft windows_10_2004 · microsoft windows_10_20h2 · microsoft windows_10_21h1 · and 2 more
0.07EPSS
CVE-2025-5419
Exploited High 8.8

Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

google chrome · microsoft edge_chromium
0.06EPSS
CVE-2026-58644
Exploited Critical 9.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

microsoft sharepoint_server
0.06EPSS