imPC@ndo IT

CVE Tracker

56.327 CVE

CVE-2026-35616
Exploited Critical 9.8

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

fortinet forticlientems
0.89EPSS
CVE-2022-0847
Exploited High 7.8

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use th…

fedoraproject fedora · linux linux_kernel · netapp h300e_firmware · netapp h300s_firmware · and 25 more
0.89EPSS
CVE-2017-8464
Exploited High 8.8

Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows local users or remote attackers to execute …

microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_7 · and 5 more
0.89EPSS
CVE-2020-8193
Exploited Medium 6.5

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.

citrix application_delivery_controller_firmware · citrix gateway_firmware · citrix netscaler_gateway_firmware · citrix sd-wan_wanop
0.88EPSS
CVE-2026-20127
Exploited Critical 10.0

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remot…

cisco catalyst_sd-wan_manager · cisco sd-wan_vbond_orchestrator · cisco sd-wan_vsmart_controller
0.88EPSS
CVE-2023-36025
Exploited High 8.8

Windows SmartScreen Security Feature Bypass Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 9 more
0.88EPSS
CVE-2014-1776
Exploited Critical 9.8

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploited in…

microsoft internet_explorer
0.88EPSS
CVE-2021-21973
Exploited Medium 5.3

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter…

vmware cloud_foundation · vmware vcenter_server
0.88EPSS
CVE-2018-8174
Ransomware High 7.5

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, …

microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · microsoft windows_10_1803 · and 6 more
0.88EPSS
CVE-2016-9079
Exploited High 7.5

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, a…

debian debian_linux · mozilla firefox · mozilla thunderbird · redhat enterprise_linux · and 6 more
0.88EPSS
CVE-2016-6366
Exploited High 8.8

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary …

cisco adaptive_security_appliance_software · cisco asa_1000v_cloud_firewall_software · cisco pix_firewall_software
0.88EPSS
CVE-2014-6324
Exploited High 8.8

The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtai…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_server_2003 · and 2 more
0.87EPSS
CVE-2018-0802
Exploited High 7.8

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". …

microsoft office · microsoft office_compatibility_pack · microsoft word
0.87EPSS
CVE-2016-6415
Exploited High 7.5

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Assoc…

cisco ios · cisco ios_xe · cisco ios_xr
0.87EPSS
CVE-2014-4113
Exploited High 7.8

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain pr…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · and 5 more
0.87EPSS
CVE-2013-0640
Exploited High 7.8

Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as exploited in the wild in February 2013.

adobe acrobat · adobe acrobat_reader · opensuse opensuse · redhat enterprise_linux_desktop · and 5 more
0.87EPSS
CVE-2025-20362
Exploited Medium 6.5

Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to u…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.87EPSS
CVE-2020-0674
Exploited High 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CV…

microsoft internet_explorer
0.87EPSS
CVE-2017-8759
Exploited High 7.8

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."

microsoft .net_framework
0.87EPSS
CVE-2015-2426
Exploited High 8.8

Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attack…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · and 5 more
0.87EPSS
CVE-2011-2462
Exploited Critical 9.8

Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption…

adobe acrobat · adobe acrobat_reader
0.87EPSS
CVE-2018-6961
Exploited High 8.1

VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing thi…

vmware nsx_sd-wan_by_velocloud
0.86EPSS
CVE-2021-21017
Exploited High 8.8

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve…

adobe acrobat · adobe acrobat_dc · adobe acrobat_reader · adobe acrobat_reader_dc
0.86EPSS
CVE-2020-11652
Exploited Medium 6.5

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

blackberry workspaces_server · canonical ubuntu_linux · debian debian_linux · opensuse leap · and 2 more
0.86EPSS
CVE-2013-3893
Exploited High 8.8

Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that trigge…

microsoft internet_explorer
0.86EPSS