imPC@ndo IT

CVE Tracker

56.413 CVE

CVE-2017-8601
High 7.5

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engine fails to render when handling objects in memory in Microsoft Ed…

microsoft edge
0.67EPSS
CVE-2016-3213
High 8.8

The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 9 throu…

microsoft internet_explorer · microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · and 4 more
0.67EPSS
CVE-2018-8145
High 7.5

An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Chakra Scripting Engine Memory Corruption Vulne…

microsoft chakracore · microsoft edge · microsoft internet_explorer
0.67EPSS
CVE-2018-0933
High 7.5

ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". This CVE ID…

microsoft chakracore · microsoft edge
0.67EPSS
CVE-2018-0934
High 7.5

ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". This CVE ID…

microsoft chakracore · microsoft edge
0.67EPSS
CVE-2000-0630
Medium 5.0

IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability.

microsoft internet_information_server · microsoft internet_information_services
0.67EPSS
CVE-2006-1016
High 7.5

Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Windows XP before SP1, allows remote attackers to execute arbitrary code via JavaScript that calls IsComponentInstalled with a long first argum…

microsoft internet_explorer
0.67EPSS
CVE-2010-2551
High 7.8

The SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate an internal variable in an SMB packet, which allows remote attackers to cause a denial of service (system hang) via a crafted…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.67EPSS
CVE-2015-6133
High 7.2

Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Windows Library Loading Remote Code …

microsoft windows_10 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · and 2 more
0.67EPSS
CVE-2018-8139
High 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-…

microsoft chakracore · microsoft edge
0.67EPSS
CVE-2018-0953
High 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-…

microsoft chakracore · microsoft edge
0.67EPSS
CVE-2018-0980
High 7.5

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique …

microsoft chakracore · microsoft edge
0.67EPSS
CVE-2022-23305
Critical 9.8

By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate …

apache log4j · broadcom brocade_sannav · netapp snapmanager · oracle advanced_supply_chain_planning · and 24 more
0.67EPSS
CVE-2025-55752
High 7.5

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query paramete…

apache tomcat
0.67EPSS
CVE-2008-4844
High 9.3

Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs,…

microsoft internet_explorer
0.67EPSS
CVE-2016-7240
High 7.5

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerabilit…

microsoft edge
0.66EPSS
CVE-2022-3229
Critical 9.8

Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this no…

unifiedremote unified_remote
0.66EPSS
CVE-2013-3205
High 9.3

Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.66EPSS
CVE-2007-0213
High 10.0

Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.

microsoft exchange_server
0.66EPSS
CVE-2001-0151
Medium 5.0

IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.

microsoft internet_information_services
0.66EPSS
CVE-2026-42945
High 8.1

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (f…

f5 dos · f5 nginx_gateway_fabric · f5 nginx_ingress_controller · f5 nginx_instance_manager · and 3 more
0.66EPSS
CVE-2015-5560
High 10.0

Integer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary co…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.66EPSS
CVE-2020-27130
Critical 9.1

A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within requests to an affected device.…

cisco security_manager
0.66EPSS
CVE-2019-12630
Critical 9.8

A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied conte…

cisco security_manager
0.66EPSS
CVE-2025-55315
Critical 9.9

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

microsoft asp.net_core · microsoft visual_studio_2022
0.66EPSS