imPC@ndo IT

Actively exploited vulnerabilities

770 CVE

CVE-2026-24858
Exploited Critical 9.8

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiMan…

fortinet fortianalyzer · fortinet fortimanager · fortinet fortinac-f · fortinet fortios · and 3 more
0.86EPSS
CVE-2015-0311
Exploited Critical 9.8

Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild…

adobe flash_player · microsoft edge · microsoft internet_explorer · suse linux_enterprise_desktop · and 1 more
0.86EPSS
CVE-2009-3129
Exploited High 7.8

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint …

microsoft excel · microsoft excel_viewer · microsoft office · microsoft open_xml_file_format_converter
0.86EPSS
CVE-2023-27997
Ransomware Critical 9.8

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, ver…

fortinet fortios · fortinet fortiproxy
0.86EPSS
CVE-2017-8570
Exploited High 7.8

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0243.

microsoft office
0.86EPSS
CVE-2020-3580
Ransomware Medium 6.1

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.86EPSS
CVE-2023-24955
Ransomware High 7.2

Microsoft SharePoint Server Remote Code Execution Vulnerability

microsoft sharepoint_enterprise_server · microsoft sharepoint_server
0.85EPSS
CVE-2025-33053
Exploited High 8.8

External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.85EPSS
CVE-2014-0322
Exploited High 8.8

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in J…

microsoft internet_explorer
0.85EPSS
CVE-2013-3906
Exploited High 7.8

GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execute arbitrary code via a crafted TIFF ima…

microsoft excel_viewer · microsoft lync · microsoft office · microsoft office_compatibility_pack · and 4 more
0.85EPSS
CVE-2021-1675
Ransomware High 7.8

Windows Print Spooler Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · and 11 more
0.85EPSS
CVE-2023-36847
Exploited Medium 5.3

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php…

juniper junos
0.85EPSS
CVE-2026-3055
Exploited Critical 9.8

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
0.84EPSS
CVE-2024-21762
Ransomware Critical 9.8

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0…

fortinet fortios · fortinet fortiproxy
0.84EPSS
CVE-2024-38112
Exploited High 7.5

Windows MSHTML Platform Spoofing Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 10 more
0.84EPSS
CVE-2017-0213
Ransomware High 7.3

Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerabi…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_10_1703 · and 6 more
0.84EPSS
CVE-2009-3953
Exploited High 8.8

The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclarat…

adobe acrobat · opensuse opensuse · suse linux_enterprise · suse linux_enterprise_debuginfo
0.84EPSS
CVE-2020-3161
Exploited Critical 9.8

A vulnerability in the web server for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition. The vulnerability is due to …

cisco 8831_firmware · cisco ip_phone_7811_firmware · cisco ip_phone_7821_firmware · cisco ip_phone_7841_firmware · and 9 more
0.84EPSS
CVE-2012-1889
Exploited High 8.8

Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

microsoft xml_core_services
0.84EPSS
CVE-2019-0193
Exploited High 7.2

In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen …

apache solr · debian debian_linux
0.84EPSS
CVE-2012-0151
Exploited High 7.8

The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the dig…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · and 1 more
0.84EPSS
CVE-2016-5195
Exploited High 7.0

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016…

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · and 14 more
0.84EPSS
CVE-2021-20021
Ransomware Critical 9.8

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

sonicwall email_security · sonicwall email_security_appliance_3300_firmware · sonicwall email_security_appliance_4300_firmware · sonicwall email_security_appliance_5000_firmware · and 7 more
0.83EPSS
CVE-2026-20230
Exploited High 8.6

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks thro…

cisco unified_communications_manager
0.83EPSS
CVE-2020-3992
Ransomware Critical 9.8

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine…

vmware cloud_foundation · vmware esxi
0.83EPSS