imPC@ndo IT

CVE Tracker

56.413 CVE

CVE-2022-21919
Exploited High 7.0

Windows User Profile Service Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · and 13 more
0.03EPSS
CVE-2021-38649
Exploited High 7.0

Open Management Infrastructure Elevation of Privilege Vulnerability

microsoft azure_automation_state_configuration · microsoft azure_automation_update_management · microsoft azure_diagnostics_\(lad\) · microsoft azure_open_management_infrastructure · and 7 more
0.03EPSS
CVE-2022-40139
Exploited High 7.2

Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, whi…

trendmicro apex_one
0.03EPSS
CVE-2021-38645
Exploited High 7.8

Open Management Infrastructure Elevation of Privilege Vulnerability

microsoft azure_automation_state_configuration · microsoft azure_automation_update_management · microsoft azure_diagnostics_\(lad\) · microsoft azure_security_center · and 6 more
0.03EPSS
CVE-2024-36971
Exploited High 7.8

In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first…

debian debian_linux · linux linux_kernel
0.03EPSS
CVE-2020-0878
Ransomware Medium 4.2

<p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker …

microsoft chakracore · microsoft edge · microsoft internet_explorer
0.03EPSS
CVE-2024-38226
Exploited High 7.3

Microsoft Publisher Security Feature Bypass Vulnerability

microsoft office_2019 · microsoft office_long_term_servicing_channel · microsoft publisher
0.03EPSS
CVE-2020-24557
Exploited High 7.8

A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege e…

trendmicro apex_one · trendmicro worry-free_business_security
0.03EPSS
CVE-2021-31201
Exploited Medium 5.2

Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · and 12 more
0.03EPSS
CVE-2025-59230
Exploited High 7.8

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 12 more
0.03EPSS
CVE-2022-41049
Exploited Medium 5.4

Windows Mark of the Web Security Feature Bypass Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 8 more
0.02EPSS
CVE-2026-21519
Exploited High 7.8

Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · and 8 more
0.02EPSS
CVE-2025-62221
Exploited High 7.8

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_23h2 · and 6 more
0.02EPSS
CVE-2019-0880
Exploited High 7.8

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · and 9 more
0.02EPSS
CVE-2022-41073
Ransomware High 7.8

Windows Print Spooler Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 12 more
0.02EPSS
CVE-2022-0028
Exploited High 8.6

A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (vir…

paloaltonetworks pan-os
0.02EPSS
CVE-2023-20109
Exploited Medium 6.6

A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitr…

cisco ios · cisco ios_xe
0.02EPSS
CVE-2026-56155
Exploited High 7.8

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_server_2012 · microsoft windows_server_2016 · and 3 more
0.02EPSS
CVE-2019-1130
Ransomware High 7.8

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · and 10 more
0.02EPSS
CVE-2025-21391
Exploited High 7.1

Windows Storage Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 9 more
0.02EPSS
CVE-2025-53521
Exploited Critical 9.8

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

f5 big-ip_access_policy_manager
0.02EPSS
CVE-2026-11645
Exploited High 8.8

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

google chrome
0.02EPSS
CVE-2025-24993
Exploited High 7.8

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.02EPSS
CVE-2017-12232
Exploited Medium 6.5

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a d…

cisco ios
0.02EPSS
CVE-2025-32706
Exploited High 7.8

Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.02EPSS