imPC@ndo IT

CVE Tracker

56.413 CVE

CVE-2017-6663
Exploited Medium 6.5

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. Mo…

cisco ios · cisco ios_xe
0.02EPSS
CVE-2025-3928
Exploited High 8.8

Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46…

commvault commvault
0.02EPSS
CVE-2021-41357
Exploited High 7.8

Win32k Elevation of Privilege Vulnerability

microsoft windows_10_2004 · microsoft windows_10_20h2 · microsoft windows_10_21h1 · microsoft windows_11_21h2 · and 3 more
0.02EPSS
CVE-2021-40450
Exploited High 7.8

Win32k Elevation of Privilege Vulnerability

microsoft windows_10_1809 · microsoft windows_10_1909 · microsoft windows_10_2004 · microsoft windows_10_20h2 · and 6 more
0.02EPSS
CVE-2017-12238
Exploited Medium 6.5

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resultin…

cisco ios
0.02EPSS
CVE-2026-3910
Exploited High 8.8

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

google chrome
0.02EPSS
CVE-2025-24991
Exploited Medium 5.5

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.02EPSS
CVE-2022-41091
Ransomware Medium 5.4

Windows Mark of the Web Security Feature Bypass Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 8 more
0.02EPSS
CVE-2025-24984
Exploited Medium 4.6

Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 10 more
0.02EPSS
CVE-2025-0111
Exploited Medium 6.5

An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user. You can gre…

paloaltonetworks pan-os
0.02EPSS
CVE-2019-0797
Exploited High 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0808.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · and 9 more
0.02EPSS
CVE-2019-1129
Ransomware High 7.8

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.

microsoft windows_10_1703 · microsoft windows_10_1709 · microsoft windows_10_1803 · microsoft windows_10_1809 · and 4 more
0.02EPSS
CVE-2024-7262
Exploited High 7.8

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click…

kingsoft wps_office
0.02EPSS
CVE-2025-30400
Exploited High 7.8

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_22h2 · and 6 more
0.02EPSS
CVE-2023-28229
Exploited High 7.0

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 9 more
0.02EPSS
CVE-2025-22226
Exploited High 7.1

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx proce…

vmware cloud_foundation · vmware esxi · vmware fusion · vmware telco_cloud_infrastructure · and 2 more
0.02EPSS
CVE-2025-24989
Exploited High 8.2

An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected cust…

microsoft power_pages
0.02EPSS
CVE-2025-21590
Exploited Medium 4.4

An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access to the shell is able to inject arbitrar…

juniper junos
0.02EPSS
CVE-2022-41033
Exploited High 7.8

Windows COM+ Event System Service Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 12 more
0.02EPSS
CVE-2025-32709
Exploited High 7.8

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.02EPSS
CVE-2024-38107
Exploited High 7.8

Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 10 more
0.02EPSS
CVE-2026-3909
Exploited High 8.8

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

google chrome
0.02EPSS
CVE-2025-22224
Exploited Critical 9.3

VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual mach…

vmware cloud_foundation · vmware esxi · vmware telco_cloud_infrastructure · vmware telco_cloud_platform · and 1 more
0.02EPSS
CVE-2025-21334
Exploited High 7.8

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_22h2 · microsoft windows_11_23h2 · and 3 more
0.02EPSS
CVE-2025-21418
Exploited High 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · and 10 more
0.02EPSS