imPC@ndo IT

CVE Tracker

56.413 CVE

CVE-2021-31196
Exploited High 7.2

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.54EPSS
CVE-2022-21971
Exploited High 7.8

Windows Runtime Remote Code Execution Vulnerability

microsoft windows_10_1809 · microsoft windows_10_1909 · microsoft windows_10_20h2 · microsoft windows_10_21h1 · and 5 more
0.54EPSS
CVE-2021-22941
Ransomware Critical 9.8

Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.

citrix sharefile_storagezones_controller
0.54EPSS
CVE-2019-0808
Exploited High 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0797.

microsoft windows_7 · microsoft windows_server_2008
0.53EPSS
CVE-2015-1642
Exploited High 7.8

Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

microsoft office
0.53EPSS
CVE-2019-0541
Exploited High 8.8

A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explo…

microsoft excel_viewer · microsoft internet_explorer · microsoft office · microsoft office_365_proplus · and 1 more
0.53EPSS
CVE-2012-2539
Exploited High 7.8

Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, ak…

microsoft office_compatibility_pack · microsoft office_web_apps · microsoft office_word_viewer · microsoft sharepoint_server · and 1 more
0.53EPSS
CVE-2020-1054
Exploited High 7.8

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1143.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · and 13 more
0.53EPSS
CVE-2019-13272
Exploited High 7.8

In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-…

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · and 18 more
0.52EPSS
CVE-2024-43461
Exploited High 8.8

Windows MSHTML Platform Spoofing Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.52EPSS
CVE-2021-28550
Exploited High 8.8

Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary c…

adobe acrobat · adobe acrobat_dc · adobe acrobat_reader · adobe acrobat_reader_dc
0.52EPSS
CVE-2009-1537
Exploited High 8.8

Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a cr…

microsoft directx · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2003 · and 1 more
0.51EPSS
CVE-2024-38094
Ransomware High 7.2

Microsoft SharePoint Remote Code Execution Vulnerability

microsoft sharepoint_server
0.51EPSS
CVE-2021-20023
Ransomware Medium 4.9

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

sonicwall email_security · sonicwall email_security_appliance_3300_firmware · sonicwall email_security_appliance_4300_firmware · sonicwall email_security_appliance_5000_firmware · and 7 more
0.50EPSS
CVE-2020-12812
Ransomware Critical 9.8

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of…

fortinet fortios
0.49EPSS
CVE-2021-22017
Exploited Medium 5.3

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being acc…

vmware vcenter_server
0.49EPSS
CVE-2023-5217
Exploited High 8.8

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

apple ipados · apple iphone_os · debian debian_linux · fedoraproject fedora · and 7 more
0.49EPSS
CVE-2023-28252
Ransomware High 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 9 more
0.49EPSS
CVE-2020-16009
Exploited High 8.8

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

cefsharp cefsharp · debian debian_linux · fedoraproject fedora · google chrome · and 4 more
0.49EPSS
CVE-2020-9715
Exploited High 7.8

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

adobe acrobat_dc · adobe acrobat_reader_dc
0.48EPSS
CVE-2006-2492
Exploited High 8.8

Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 200…

microsoft office · microsoft works_suite
0.48EPSS
CVE-2011-1889
Exploited Critical 9.8

The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."…

microsoft forefront_threat_management_gateway
0.48EPSS
CVE-2021-26829
Exploited Medium 5.4

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.

scadabr scadabr
0.48EPSS
CVE-2013-2094
Exploited High 8.4

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.

linux linux_kernel
0.48EPSS
CVE-2014-4077
Exploited High 7.8

Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a sandbox protection mechanism via a crafted PD…

microsoft office_2007_ime · microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · and 1 more
0.48EPSS